CVE-2023-50782

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*

Configuration 5 (hide)

OR cpe:2.3:a:couchbase:couchbase_server:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:couchbase:couchbase_server:7.6.1:*:*:*:*:*:*:*

History

27 Sep 2024, 19:15

Type Values Removed Values Added
References
  • {'url': 'https://www.couchbase.com/alerts/', 'tags': ['Third Party Advisory'], 'source': 'secalert@redhat.com'}

05 Sep 2024, 16:43

Type Values Removed Values Added
CPE cpe:2.3:a:python-cryptography_project:python-cryptography:*:*:*:*:*:*:*:* cpe:2.3:a:couchbase:couchbase_server:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*
cpe:2.3:a:couchbase:couchbase_server:7.6.0:*:*:*:*:*:*:*
References () https://www.couchbase.com/alerts/ - () https://www.couchbase.com/alerts/ - Third Party Advisory
First Time Couchbase
Cryptography.io cryptography
Couchbase couchbase Server
Cryptography.io

26 Jul 2024, 22:15

Type Values Removed Values Added
References
  • () https://www.couchbase.com/alerts/ -

14 Feb 2024, 17:52

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:python-cryptography_project:python-cryptography:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
First Time Redhat
Python-cryptography Project
Python-cryptography Project python-cryptography
Redhat ansible Automation Platform
Redhat update Infrastructure
Redhat enterprise Linux
CWE CWE-208 CWE-203
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://access.redhat.com/security/cve/CVE-2023-50782 - () https://access.redhat.com/security/cve/CVE-2023-50782 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2254432 - () https://bugzilla.redhat.com/show_bug.cgi?id=2254432 - Issue Tracking, Vendor Advisory

05 Feb 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 21:15

Updated : 2024-09-27 19:15


NVD link : CVE-2023-50782

Mitre link : CVE-2023-50782

CVE.ORG link : CVE-2023-50782


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • update_infrastructure
  • ansible_automation_platform

couchbase

  • couchbase_server

cryptography.io

  • cryptography
CWE
CWE-203

Observable Discrepancy

CWE-208

Observable Timing Discrepancy