Логотип exploitDog
bind:CVE-2024-21484
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21484

Количество 4

Количество 4

redhat логотип

CVE-2024-21484

около 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-21484

около 2 лет назад

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rh63-9qcf-83gf

около 2 лет назад

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-00774

около 2 лет назад

Уязвимость реализации стандарта PKCS#1 v1.5 криптографической библиотеки jsrsasign, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-21484

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-21484

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-rh63-9qcf-83gf

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

CVSS3: 7.5
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-00774

Уязвимость реализации стандарта PKCS#1 v1.5 криптографической библиотеки jsrsasign, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher) или атаку Марвина (Marvin)

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу