Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3ww4-gg4f-jr7f

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Пакеты

Наименование

cryptography

pip
Затронутые версииВерсия исправления

< 42.0.0

42.0.0

EPSS

Процентиль: 63%
0.01118
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208
CWE-385

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
redhat
больше 2 лет назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
nvd
больше 2 лет назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
msrc
6 месяцев назад

Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659

CVSS3: 7.5
debian
больше 2 лет назад

A flaw was found in the python-cryptography package. This issue may al ...

EPSS

Процентиль: 63%
0.01118
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208
CWE-385