Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh63-9qcf-83gf

Опубликовано: 19 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

Impact

RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.

Patches

update to jsrsasign 11.0.0.

Workarounds

Find and replace RSA and RSAOAEP decryption with other crypto library.

References

https://people.redhat.com/~hkario/marvin/ https://github.com/kjur/jsrsasign/issues/598 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484

Пакеты

Наименование

jsrsasign

npm
Затронутые версииВерсия исправления

< 11.0.0

11.0.0

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
nvd
около 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость реализации стандарта PKCS#1 v1.5 криптографической библиотеки jsrsasign, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-203