Skip to content

Commit 925a4f3

Browse files
authored
Update documentation/modules/rn-2.5.adoc
1 parent ff94f1d commit 925a4f3

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

documentation/modules/rn-2.5.adoc

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -137,7 +137,7 @@ This release has the following resolved issues:
137137

138138
.Flaw was found in jsrsasign package which is vulnerable to Observable Discrepancy
139139

140-
Versions of the package `jsrsasign` before 11.0.0, used in previous releases of {project-short}, are vulnerable to Observable Discrepancy in the RSA PKCS1.5 or RSA-OAEP decryption process. This discrepancy means an attacker could decrypt ciphertexts by exploiting this vulnerability. However, exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. This issue has been resolved in {project-short} 2.5.5 by upgrading the package 'jsrasign` to version 11.0.0.
140+
Versions of the package `jsrsasign` before 11.0.0, used in previous releases of {project-short}, are vulnerable to Observable Discrepancy in the RSA PKCS1.5 or RSA-OAEP decryption process. This discrepancy means an attacker could decrypt ciphertexts by exploiting this vulnerability. However, exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. This issue has been resolved in {project-short} 2.5.5 by upgrading the package `jsrasign` to version 11.0.0.
141141

142142
For more information, see link:https://access.redhat.com/security/cve/CVE-2024-21484[CVE-2024-21484].
143143

0 commit comments

Comments
 (0)