amzn / amzn/amazon-pay-api-sdk-php

CVE-2023-49316 in dependency phpseclib/phpseclib

Open
#42 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
PHP
Stars
51
Forks
33
PR merge metrics
No merged PRs in 30d

Description

Currently [phpseclib/phpseclib](https://github.com/phpseclib/phpseclib) is affected by [CVE-2023-49316](https://github.com/advisories/GHSA-jpr7-q523-hx25)

They fixed it with release of [Version 3.0.34](https://github.com/phpseclib/phpseclib/releases/tag/3.0.34) 3 days ago.

Please concern updating your requirements with the next version.

Contributor guide

Open the contributing guide

Research direction

Start by locating the project's dependency requirements for phpseclib/phpseclib. Update the requirement to include version 3.0.34, then verify that dependency installation resolves to the fixed release and that the existing project checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.