Skip to content

Conversation

@avara1986
Copy link
Member

@avara1986 avara1986 commented Oct 28, 2020

GHSA-hggm-jpg3-v476
moderate severity
Vulnerable versions: < 3.2
Patched version: 3.2
Impact
RSA decryption was vulnerable to Bleichenbacher timing vulnerabilities, which would impact people using RSA decryption in online scenarios.

Patches
This is fixed in cryptography 3.2. pyca/cryptography@58494b4 is the resolving commit.

@avara1986 avara1986 merged commit 8bc2ae5 into master Oct 28, 2020
@avara1986 avara1986 deleted the feature/cryptography-3.2 branch October 28, 2020 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants