A AegiFlow
MEDIUMCVSS 5.4

CVE-2020-7069

CVE-2020-7069 updated by NVD

Modified
2026-09-20
Sources
nvd

Summary

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object], [object Object]

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.