Rhonabwy Project Rhonabwy vulnerabilities
3 known vulnerabilities affecting rhonabwy_project/rhonabwy.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2024-25714CRITICALCVSS 9.8≤ 1.1.32024-02-11
CVE-2024-25714 [CRITICAL] CWE-203 CVE-2024-25714: In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
nvdosv
CVE-2022-38493HIGHCVSS 7.5≥ 0.9.99, < 1.1.62022-08-20
CVE-2022-38493 [HIGH] CWE-327 CVE-2022-38493: Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP
Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.
nvdosv
CVE-2022-32096HIGHCVSS 7.5fixed in 1.1.52022-07-13
CVE-2022-32096 [HIGH] CWE-120 CVE-2022-32096: Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component r_jwe_aesgcm_ke
Rhonabwy before v1.1.5 was discovered to contain a buffer overflow via the component r_jwe_aesgcm_key_unwrap. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted JWE token.
nvdosv