CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.0 are vulnerable to a critical sandbox escape flaw in the openssl_encrypt function, allowing attackers to exploit dunder attribute traversal techniques to access restricted functions. This vulnerability enables the execution of arbitrary system commands from plugin code, posing a significant risk to systems utilizing affected versions. Organizations using OpenSSL should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and execute arbitrary system commands from plugin code.
Related CVEs
Other vulnerabilities affecting the same vendor(s)