ZeroHour

CVE-2022-38493

CVSS 3.1
7.5 high
EPSS
<1%p26
Published
()
Modified
Description

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

Vendors
rhonabwy project
Products
rhonabwy
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.