icon

We found results for “

CVE-2024-21484

Good to know:

icon

Date: January 22, 2024

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Observable Discrepancy

CWE-203

Top Fix

icon

Upgrade Version

Upgrade to version jsrsasign - 11.0.0;jsrsasign - 11.0.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us