CyberRota Analysis
AI-GeneratedOpenSSL versions prior to 1.4.9 are vulnerable due to inadequate validation of server URLs in the login and register_with_email functions, allowing the acceptance of unencrypted HTTP URLs and unconfigured hosts. This flaw enables attackers on the network path to intercept sensitive credentials such as client IDs, passwords, and JWTs, potentially leading to complete account takeover on keyserver systems. Organizations using affected versions should prioritize patching to mitigate the risk of credential theft and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserver account takeover.
Related CVEs
Other vulnerabilities affecting the same vendor(s)