/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-46809

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-46809

CGA ID

CGA-39r9-5g8p-2vmc

Description

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

References

  • https://images.chainguard.dev/security/CGA-39r9-5g8p-2vmc

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images