CVE-2023-46809

Sept. 7, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Node.js

Source

support@hackerone.com

Tags

CVE-2023-46809 details

Published : Sept. 7, 2024, 4:15 p.m.
Last Modified : Sept. 7, 2024, 4:15 p.m.

Description

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.