Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-38493

Опубликовано: 20 авг. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

1.1.8-1
esm-apps/jammy

needed

esm-apps/noble

not-affected

1.1.8-1
esm-infra/focal

DNE

focal

DNE

jammy

needed

kinetic

not-affected

1.1.8-1
lunar

not-affected

1.1.8-1
mantic

not-affected

1.1.8-1

Показывать по

EPSS

Процентиль: 24%
0.0008
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

CVSS3: 7.5
debian
больше 3 лет назад

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA priva ...

EPSS

Процентиль: 24%
0.0008
Низкий

7.5 High

CVSS3