Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-46809

Опубликовано: 07 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

18.19.1+dfsg-6ubuntu5
esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

needed

esm-apps/noble

not-affected

18.19.1+dfsg-6ubuntu5
esm-apps/resolute

not-affected

18.19.1+dfsg-6ubuntu5
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present

Показывать по

EPSS

Процентиль: 67%
0.01302
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
больше 2 лет назад

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

CVSS3: 7.4
nvd
почти 2 года назад

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

CVSS3: 7.4
debian
почти 2 года назад

Node.js versions which bundle an unpatched version of OpenSSL or run a ...

CVSS3: 7.4
github
почти 2 года назад

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

CVSS3: 5.9
fstec
больше 2 лет назад

Уязвимость функции PrivateDecrypt() криптографической библиотеки программной платформы Node.js, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

EPSS

Процентиль: 67%
0.01302
Низкий

7.4 High

CVSS3