Executive brief
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Affected products
- PyPI cryptography
Junglewise Threat Intelligence
CVE-2020-25659 · Severity: low · CVSS 3.1 · Published 2021-01-11
Technologies: cryptography (PyPI). Vendors: PyPI.
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.