Sensitive information sent insecurely In jwcrypto
Description
jwcrypto lacks the Random Filling protection mechanism The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 0.3.2 | ||
debian 14 | 0.3.2-1 | ||
debian 12 | 0.3.2-1 | ||
debian 13 | 0.3.2-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.