{"id":"GHSA-pm77-c4q7-3fwj","summary":"Improper Certificate Validation in Heartland & Global Payments PHP SDK","details":"Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.","aliases":["CVE-2019-20455"],"modified":"2024-02-17T05:26:24.182590Z","published":"2021-10-12T16:31:12Z","database_specific":{"cwe_ids":["CWE-295"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-10-08T22:58:55Z","nvd_published_at":"2020-02-14T16:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-20455"},{"type":"WEB","url":"https://github.com/globalpayments/php-sdk/pull/8"},{"type":"WEB","url":"https://github.com/globalpayments/php-sdk/pull/8/commits/c86e18f28c5eba0d6ede7d557756d978ea83d3c9"},{"type":"PACKAGE","url":"https://github.com/globalpayments/php-sdk"},{"type":"WEB","url":"https://github.com/globalpayments/php-sdk/compare/1.3.3...2.0.0"},{"type":"WEB","url":"https://github.com/globalpayments/php-sdk/releases/tag/2.0.0"},{"type":"WEB","url":"https://winterdragon.ca/global-payments-vulnerability"}],"affected":[{"package":{"name":"globalpayments/php-sdk","ecosystem":"Packagist","purl":"pkg:composer/globalpayments/php-sdk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.3.1","1.3.2","1.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-pm77-c4q7-3fwj/GHSA-pm77-c4q7-3fwj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}