cbcvebase.
CVE-2023-50782
published 2024-02-05

CVE-2023-50782: A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.12%
62.4th percentile
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Affected

15 ranges
VendorProductVersion rangeFixed in
couchbasecouchbase_server
couchbasecouchbase_server
cryptography.iocryptography< 42.0.042.0.0
cryptography.iocryptography>= 0 < 42.0.042.0.0
debianpython-cryptography< python-cryptography 42.0.5-1 (forky)python-cryptography 42.0.5-1 (forky)
msrcazl3_python-cryptography_3.3.2-5_on_azure_linux_3.0
msrcazl3_python-cryptography_42.0.5-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_python-cryptography_3.3.2-7_on_cbl_mariner_2.0
paloaltopan-os
redhatansible_automation_platform
redhatenterprise_linux
redhatenterprise_linux
redhatupdate_infrastructure

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.