Executive brief
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
Affected products
- PyPI rsa
Junglewise Threat Intelligence
CVE-2020-25658 · Severity: low · CVSS 3.1 · Published 2020-11-12
Technologies: rsa (PyPI). Vendors: PyPI.
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.