CVE-2013-3587
published 2020-02-21CVE-2013-3587: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which…
PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
6.05%
92.6th percentile
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | arx | 5.0.0 – 5.3.1 | — |
| f5 | arx | 6.0.0 – 6.4.0 | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_access_policy_manager | 11.0.0 – 11.6.1 | — |
| f5 | big-ip_access_policy_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 11.3.0 – 11.6.1 | — |
| f5 | big-ip_advanced_firewall_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 11.0.0 – 11.6.1 | — |
| f5 | big-ip_analytics | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 11.4.0 – 11.6.1 | — |
| f5 | big-ip_application_acceleration_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_application_security_manager | 11.0.0 – 11.6.1 | — |
| f5 | big-ip_application_security_manager | 12.0.0 – 12.1.2 | — |
| f5 | big-ip_application_security_manager | 9.2.0 – 9.4.8 | — |
| f5 | big-ip_edge_gateway | 10.1.0 – 10.2.4 | — |
| f5 | big-ip_edge_gateway | 11.0.0 – 11.3.0 | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_link_controller | 10.0.0 – 10.2.4 | — |
| f5 | big-ip_link_controller | 11.0.0 – 11.6.1 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
BREACH attack against HTTP compression
vendor_redhat·2013-08-02·CVSS 2.6
CVE-2013-3587 [LOW] BREACH attack against HTTP compression
BREACH attack against HTTP compression
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
Statement: This issue is not planned to be addressed in the version of httpd as shipped with Red Hat Enterprise Linux 5 and 6. More details and possible mitigations are mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=995168#c5
Package: httpd (Red Hat Enterprise Linux 5) - Will not
GHSA
GHSA-hh3m-fgxm-fq25: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da
ghsa_unreviewed·2022-05-05·CVSS 2.6
CVE-2013-3587 [LOW] CWE-200 GHSA-hh3m-fgxm-fq25: The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted da
The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain plaintext secret values by observing length differences during a series of guesses in which a string in an HTTP request URL potentially matches an unknown string in an HTTP response body, aka a "BREACH" attack, a different issue than CVE-2012-4929.
No detection rules found.
No public exploits indexed.
RFC
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
rfc·2023-09-01
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Internet Engineering Task Force (IETF) D. Fett
Request for Comments: 9449 Authlete
Category: Standards Track B. Campbell
ISSN: 2070-1721 Ping Identity
J. Bradley
Yubico
T. Lodderstedt
Tuconic
M. Jones
Self-Issued Consulting
D. Waite
Ping Identity
September 2023
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Abstract
This document describes a mechanism for sender-constraining OAuth 2.0
tokens via a proof-of-possession mechanism on the application level.
This mechanism allows for the detection of replay attacks with access
and refresh tokens.
Status of This Memo
This is an Internet Standards Track document.
This document is a product of the Internet Engineering Task Force
(IETF). It represents the consensus of the IETF community. It has
received public review and has been appr
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
HackerOne
SSL BREACH attack (CVE-2013-3587)
hackerone·2017-07-30·CVSS 5.9
CVE-2013-3587 [MEDIUM] SSL BREACH attack (CVE-2013-3587)
SSL BREACH attack (CVE-2013-3587)
Hello security team,
The site legalrobot.com is potentially vulnerable to the BREACH attack.
Allowing an attacker the ability to:
- Inject partial chosen plaintext into a victim's requests
- Measure the size of encrypted traffic
- can leverage information leaked by compression to recover targeted parts of the plaintext.
BREACH (Browser Reconnaissance & Exfiltration via Adaptive Compression of Hypertext) is a category of vulnerabilities and not a specific instance affecting a specific piece of software. To be vulnerable, a web application must:
Be served from a server that uses HTTP-level compression
Reflect user-input in HTTP response bodies
Reflect a secret (such as a CSRF token) in HTTP response bodies
Mitigations to fix this include:
- Disabling H
HackerOne
Big Bug in SSL : breach compression attack (CVE-2013-3587) affect imgur.com
hackerone·2016-01-21·CVSS 5.9
CVE-2013-3587 [MEDIUM] Big Bug in SSL : breach compression attack (CVE-2013-3587) affect imgur.com
Big Bug in SSL : breach compression attack (CVE-2013-3587) affect imgur.com
Hi imgur Security Team,
This is an urgent issue and wish you fix it as soon as possible ...
so this web application " imgur.com " " is potentially vulnerable to the BREACH attack.
An attacker with the ability to:
Inject partial chosen plaintext into a victim's requests
Measure the size of encrypted traffic
can leverage information leaked by compression to recover targeted parts of the plaintext.
BREACH (Browser Reconnaissance & Exfiltration via Adaptive Compression of Hypertext) is a category of vulnerabilities and not a specific instance affecting a specific piece of software. To be vulnerable, a web application must:
Be served from a server that uses HTTP-level compression
Reflect user-input in HTTP respon
Bugzilla
CVE-2013-3587 BREACH attack against HTTP compression
bugzilla·2013-08-08·CVSS 5.9
CVE-2013-3587 [MEDIUM] CVE-2013-3587 BREACH attack against HTTP compression
CVE-2013-3587 BREACH attack against HTTP compression
Angelo Prado, Neal Harris and Yoel Gluck reported [1],[2] that SSL/TLS attacks are still viable via a "BREACH" (Browser Reconnaissance & Exfiltration via Adaptive Compression of Hypertext) attack, which they describe as:
While CRIME was mitigated by disabling TLS/SPDY compression (and by modifying gzip to allow for explicit separation of compression contexts in SPDY), BREACH attacks HTTP responses. These are compressed using the common HTTP compression, which is much more common than TLS-level compression. This allows essentially the same attack demonstrated by Duong and Rizzo, but without relying on TLS-level compression (as they anticipated).
BREACH is a category of vulnerabilities and not a specific instance affecting a specific pi
http://breachattack.com/http://github.com/meldium/breach-mitigation-railshttp://security.stackexchange.com/questions/20406/is-http-compression-safe#20407http://slashdot.org/story/13/08/05/233216http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdfhttp://www.kb.cert.org/vuls/id/987798https://bugzilla.redhat.com/show_bug.cgi?id=995168https://hackerone.com/reports/254895https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3Ehttps://support.f5.com/csp/article/K14634https://www.blackhat.com/us-13/briefings.html#Pradohttps://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/http://breachattack.com/http://github.com/meldium/breach-mitigation-railshttp://security.stackexchange.com/questions/20406/is-http-compression-safe#20407http://slashdot.org/story/13/08/05/233216http://www.iacr.org/cryptodb/archive/2002/FSE/3091/3091.pdfhttp://www.kb.cert.org/vuls/id/987798https://bugzilla.redhat.com/show_bug.cgi?id=995168https://hackerone.com/reports/254895https://lists.apache.org/thread.html/r7f0e9cfd166934172d43ca4c272b8bdda4a343036229d9937affd1e1%40%3Cdev.httpd.apache.org%3Ehttps://support.f5.com/csp/article/K14634https://www.blackhat.com/us-13/briefings.html#Pradohttps://www.djangoproject.com/weblog/2013/aug/06/breach-and-django/
2020-02-21
Published