Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21486
HistorySep 11, 2019 - 5:23 a.m.

Information Disclosure

2019-09-1105:23:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
197

0.015 Low

EPSS

Percentile

87.1%

OpenSSL is vulnerable to information disclosure. It is possible because a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key can be recovered using a Bleichenbacher padding oracle attack after an attacker is notified with status of decryption attempt. The vulnerability only affect unless a certificate together with the private RSA key to the CMS_decrypt or PKCS7_decrypt functions to select the correct recipient info to decrypt are used.

References