PT-2023-30681 · Upydev · Upydev

Gxx777

·

Published

2023-11-20

·

Updated

2023-11-29

·

CVE-2023-48051

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions upydev version 0.4.3
Description An issue in /upydev/keygen.py allows attackers to decrypt sensitive information via weak encryption padding.
Recommendations For upydev version 0.4.3, consider disabling the use of the /upydev/keygen.py script until a patch is available to prevent attackers from decrypting sensitive information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-48051
GHSA-QC4J-HRJ6-CPPF
PYSEC-2023-302

Affected Products

Upydev