Marvin Attack of RSA and RSAOAEP decryption in jsrsasign
Description
Published to the GitHub Advisory Database
Jan 19, 2024
Reviewed
Jan 19, 2024
Published by the National Vulnerability Database
Jan 22, 2024
Last updated
Feb 27, 2024
Impact
RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.
Patches
update to jsrsasign 11.0.0.
Workarounds
Find and replace RSA and RSAOAEP decryption with other crypto library.
References
https://people.redhat.com/~hkario/marvin/
kjur/jsrsasign#598
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484
References