A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ansible_automation_platform | Redhat | 2.0 (including) | 2.0 (including) |
Python-cryptography | Ubuntu | bionic | * |
Python-cryptography | Ubuntu | esm-infra/bionic | * |
Python-cryptography | Ubuntu | esm-infra/xenial | * |
Python-cryptography | Ubuntu | focal | * |
Python-cryptography | Ubuntu | jammy | * |
Python-cryptography | Ubuntu | lunar | * |
Python-cryptography | Ubuntu | mantic | * |
Python-cryptography | Ubuntu | trusty | * |
Python-cryptography | Ubuntu | upstream | * |
Python-cryptography | Ubuntu | xenial | * |