CVE-2023-50782

Source
https://cve.org/CVERecord?id=CVE-2023-50782
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50782.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-50782
Aliases
Downstream
AZL (2)
BELL (1)
CGA (36)
CLSA (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (1)
OESA (6)
openSUSE (1)
ROOT (1)
SUSE (10)
UBUNTU (1)
Related
Published
2024-02-05T20:45:49Z
Modified
2026-08-12T03:51:08Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Details

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Database specific
{
    "cna_assigner":  "redhat",
    "cwe_ids":  [
        "CWE-203"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50782.json"
}
References

Affected packages

Git / github.com/pyca/cryptography

Affected ranges

Type
GIT
Repo
https://github.com/pyca/cryptography
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*",
    "extracted_events":  [
        {
            "introduced":  "3.2"
        },
        {
            "fixed":  "42.0.0"
        },
        {
            "introduced":  "0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

3.*
3.2
3.3
3.4
35.*
35.0.0
36.*
36.0.0
37.*
37.0.0
38.*
38.0.0
39.*
39.0.0
40.*
40.0.0
41.*
41.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50782.json"