CVE-2023-46809
Last modified
CVE-2023-46809 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-46809?
How severe is CVE-2023-46809?
How do I fix CVE-2023-46809?
Are you affected by CVE-2023-46809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
