Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3ww4-gg4f-jr7f

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Python Cryptography package vulnerable to Bleichenbacher timing oracle attack

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Пакеты

Наименование

cryptography

pip
Затронутые версииВерсия исправления

< 42.0.0

42.0.0

EPSS

Процентиль: 66%
0.00521
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may al ...

EPSS

Процентиль: 66%
0.00521
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-203
CWE-208