Junglewise Threat Intelligence

CVE-2020-25659: PYSEC-2021-62 - python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5

CVE-2020-25659 · Severity: low · CVSS 3.1 · Published 2021-01-11

Technologies: cryptography (PyPI). Vendors: PyPI.

Executive brief

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

Affected products

  • PyPI cryptography

Related threats