GHSA-j225-cvw7-qrx7

Suggest an improvement
Source
https://github.com/advisories/GHSA-j225-cvw7-qrx7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-j225-cvw7-qrx7
Aliases
Downstream
CGA (2)
Published
2024-01-05T06:30:19Z
Modified
2026-07-17T21:09:30Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
Details

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

Database specific
{
    "cwe_ids":  [
        "CWE-203"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-01-05T17:25:46Z",
    "nvd_published_at":  "2024-01-05T04:15:07Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / pycryptodomex

Package

Name
pycryptodomex
View open source insights on deps.dev
Purl
pkg:pypi/pycryptodomex

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.19.1

Affected versions

3.*
3.4.1
3.4.2
3.4.3
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.11
3.4.12
3.5.1
3.6.0
3.6.1
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0
3.8.1
3.8.2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.6
3.9.7
3.9.8
3.9.9
3.10.1
3.10.3
3.10.4
3.11.0
3.12.0
3.13.0
3.14.0
3.14.1
3.15.0
3.16.0
3.17
3.18.0
3.19.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json"

PyPI / pycryptodome

Package

Name
pycryptodome
View open source insights on deps.dev
Purl
pkg:pypi/pycryptodome

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.19.1

Affected versions

3.*
3.0rc1
3.0
3.1
3.2
3.2.1
3.3
3.3.1
3.4
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.11
3.5.0
3.5.1
3.6.0
3.6.1
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0
3.8.1
3.8.2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.6
3.9.7
3.9.8
3.9.9
3.10.1
3.10.3
3.10.4
3.11.0
3.12.0
3.13.0
3.14.0
3.14.1
3.15.0
3.16.0
3.17
3.18.0
3.19.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json"