Launch Week Day 1: Announcing Security Design Review
LOW 3.7 NuGet

ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse

GHSA-qv2q-c278-pch5

Published ยท Modified

Description

The PasskeyEncipherImage method is vulnerable to information disclosure via AES-CTR nonce reuse. ImageMagick has update the documentation on its website to make it more clear that this is happening: https://imagemagick.org/cipher/

Ready to move

Start Securing

Free, no credit card | First findings in minutes