CVE-2024-23342

HIGH

ecdsa <0.18.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.

Scores

CVSS v3 7.4
EPSS 0.0062
EPSS Percentile 70.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-385 CWE-208 CWE-203
Status published
Products (2)
pypi/ecdsa 0PyPI
tlsfuzzer/ecdsa < 0.18.0
Published Jan 23, 2024
Tracked Since Feb 18, 2026