{"id":"CVE-2017-0897","details":"ExpressionEngine version 2.x \u003c 2.11.8 and version 3.x \u003c 3.5.5 create an object signing token with weak entropy. Successfully guessing the token can lead to remote code execution.","modified":"2026-04-10T03:54:34.235025Z","published":"2017-06-22T21:29:00.183Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99242"},{"type":"ADVISORY","url":"https://docs.expressionengine.com/latest/about/changelog.html#version-3-5-5"},{"type":"ADVISORY","url":"https://docs.expressionengine.com/v2/about/changelog.html#version-2-11-8"},{"type":"ADVISORY","url":"https://expressionengine.com/blog/expressionengine-3.5.5-and-2.11.8-released"},{"type":"REPORT","url":"https://hackerone.com/reports/215890"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/expressionengine/expressionengine","events":[{"introduced":"0"},{"last_affected":"0017bb5add82250eb8f3fa8252c38590e0989d38"},{"introduced":"0"},{"last_affected":"5f9a3afc6edc901323cf4240d3040ec42628de65"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.10.1"},{"introduced":"0"},{"last_affected":"3.5.1"}]}}],"versions":["2.10.1","3.5.17"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"2.0.0-public_beta"}]},{"events":[{"introduced":"0"},{"last_affected":"2.0.1-public_beta"}]},{"events":[{"introduced":"0"},{"last_affected":"2.0.2-public_beta"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.4"}]},{"events":[{"introduced":"0"},{"last_affected":"2.1.5"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.2.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.3.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.4.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.4"}]},{"events":[{"introduced":"0"},{"last_affected":"2.5.5"}]},{"events":[{"introduced":"0"},{"last_affected":"2.6.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.6.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.7.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.7.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.7.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.8.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.9.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.9.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.9.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.10.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.10.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.10.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.0"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.1"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.2"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.3"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.4"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.5"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.6"}]},{"events":[{"introduced":"0"},{"last_affected":"2.11.7"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.3"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.4"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.5"}]},{"events":[{"introduced":"0"},{"last_affected":"3.0.6"}]},{"events":[{"introduced":"0"},{"last_affected":"3.1.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.1.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.1.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.1.3"}]},{"events":[{"introduced":"0"},{"last_affected":"3.1.4"}]},{"events":[{"introduced":"0"},{"last_affected":"3.2.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.2.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3.3"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3.4"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.3"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.4"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.5"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.6"}]},{"events":[{"introduced":"0"},{"last_affected":"3.4.7"}]},{"events":[{"introduced":"0"},{"last_affected":"3.5.0"}]},{"events":[{"introduced":"0"},{"last_affected":"3.5.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.5.3"}]},{"events":[{"introduced":"0"},{"last_affected":"3.5.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-0897.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}