CVE-2023-50782
published 2024-02-05CVE-2023-50782: A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.12%
62.4th percentile
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| couchbase | couchbase_server | — | — |
| couchbase | couchbase_server | — | — |
| cryptography.io | cryptography | < 42.0.0 | 42.0.0 |
| cryptography.io | cryptography | >= 0 < 42.0.0 | 42.0.0 |
| debian | python-cryptography | < python-cryptography 42.0.5-1 (forky) | python-cryptography 42.0.5-1 (forky) |
| msrc | azl3_python-cryptography_3.3.2-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-cryptography_42.0.5-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python-cryptography_3.3.2-7_on_cbl_mariner_2.0 | — | — |
| paloalto | pan-os | — | — |
| redhat | ansible_automation_platform | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | update_infrastructure | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Ubuntu
python-cryptography vulnerability
vendor_ubuntu·2024-03-14·CVSS 7.5
CVE-2023-50782 [HIGH] python-cryptography vulnerability
Title: python-cryptography vulnerability
Summary: python-cryptography could be made to expose sensitive information over the
network.
USN-6673-1 provided a security update for python-cryptography.
This update provides the corresponding update for Ubuntu 16.04 LTS.
Original advisory details:
Hubert Kario discovered that python-cryptography incorrectly handled
errors returned by the OpenSSL API when processing incorrect padding in
RSA PKCS#1 v1.5. A remote attacker could possibly use this issue to expose
confidential or sensitive information. (CVE-2023-50782)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
python-cryptography vulnerabilities
vendor_ubuntu·2024-03-04·CVSS 7.5
CVE-2024-26130 [HIGH] python-cryptography vulnerabilities
Title: python-cryptography vulnerabilities
Summary: Several security issues were fixed in python-cryptography.
Hubert Kario discovered that python-cryptography incorrectly handled
errors returned by the OpenSSL API when processing incorrect padding in
RSA PKCS#1 v1.5. A remote attacker could possibly use this issue to expose
confidential or sensitive information. (CVE-2023-50782)
It was discovered that python-cryptography incorrectly handled memory
operations when processing mismatched PKCS#12 keys. A remote attacker could
possibly use this issue to cause python-cryptography to crash, leading to a
denial of service. This issue only affected Ubuntu 23.10. (CVE-2024-26130)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2023-50782 [HIGH] CWE-203 Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Ye
Red Hat
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
vendor_redhat·2023-12-13·CVSS 5.9
CVE-2023-50782 [MEDIUM] CWE-203 python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Statement: This vulnerability exists due to an incomplete fix for CVE-2020-25659.
The CVE-2020-25659 vulnerability presents a moderate severity concern due to its specific impact on applications utilizing RSA decryption with PKCS
Debian
CVE-2023-50782: python-cryptography - A flaw was found in the python-cryptography package. This issue may allow a remo...
vendor_debian·2023·CVSS 7.5
CVE-2023-50782 [HIGH] CVE-2023-50782: python-cryptography - A flaw was found in the python-cryptography package. This issue may allow a remo...
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 42.0.5-1)
sid: resolved (fixed in 42.0.5-1)
trixie: resolved (fixed in 42.0.5-1)
OSV
python-cryptography vulnerability
osv·2024-03-14·CVSS 7.5
CVE-2023-50782 [HIGH] python-cryptography vulnerability
python-cryptography vulnerability
USN-6673-1 provided a security update for python-cryptography.
This update provides the corresponding update for Ubuntu 16.04 LTS.
Original advisory details:
Hubert Kario discovered that python-cryptography incorrectly handled
errors returned by the OpenSSL API when processing incorrect padding in
RSA PKCS#1 v1.5. A remote attacker could possibly use this issue to expose
confidential or sensitive information. (CVE-2023-50782)
OSV
python-cryptography vulnerabilities
osv·2024-03-04·CVSS 7.5
CVE-2023-50782 [HIGH] python-cryptography vulnerabilities
python-cryptography vulnerabilities
Hubert Kario discovered that python-cryptography incorrectly handled
errors returned by the OpenSSL API when processing incorrect padding in
RSA PKCS#1 v1.5. A remote attacker could possibly use this issue to expose
confidential or sensitive information. (CVE-2023-50782)
It was discovered that python-cryptography incorrectly handled memory
operations when processing mismatched PKCS#12 keys. A remote attacker could
possibly use this issue to cause python-cryptography to crash, leading to a
denial of service. This issue only affected Ubuntu 23.10. (CVE-2024-26130)
OSV
CVE-2023-50782: A flaw was found in the python-cryptography package
osv·2024-02-05·CVSS 7.5
CVE-2023-50782 [HIGH] CVE-2023-50782: A flaw was found in the python-cryptography package
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
GHSA
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
ghsa·2024-02-05
CVE-2023-50782 [HIGH] CWE-203 Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
OSV
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
osv·2024-02-05
CVE-2023-50782 [HIGH] Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
Python Cryptography package vulnerable to Bleichenbacher timing oracle attack
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
No detection rules found.
No public exploits indexed.
2024-02-05
Published