Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21484

Опубликовано: 22 янв. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 5.9
EPSS Низкий

Описание

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key.

Workaround

The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:*
Версия до 11.0.0 (исключая)

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-203
CWE-203

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
github
около 2 лет назад

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость реализации стандарта PKCS#1 v1.5 криптографической библиотеки jsrsasign, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-203
CWE-203