Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc79-wmwr-7fjh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

In Rust SGX 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

In Rust SGX 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

EPSS

Процентиль: 66%
0.00518
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 4.9
nvd
больше 4 лет назад

In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

EPSS

Процентиль: 66%
0.00518
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-203