NA

CVE-2024-21484

Published: 22/01/2024 Updated: 06/03/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

Versions of the package jsrsasign prior to 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the malicious user to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

Vulnerable Product Search on Vulmon Subscribe to Product

jsrsasign project jsrsasign

Vendor Advisories

Description<!---->This CVE is under investigation by Red Hat Product Security ...