PT-2025-25762 · Unknown · Conda-Smithy

Jaimergp

·

Published

2025-06-17

·

Updated

2025-06-18

·

CVE-2025-49824

CVSS v4.0

1.7

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions conda-smithy versions prior to 3.47.1
Description The issue results from the use of an outdated and insecure padding scheme during RSA encryption in the travis encrypt binstar token implementation. A malicious actor with access to an oracle system can exploit this flaw by iteratively submitting modified ciphertexts and analyzing responses to infer the plaintext without possessing the private key.
Recommendations For versions prior to 3.47.1, update to version 3.47.1 to resolve the issue. As a temporary workaround, consider restricting access to the travis encrypt binstar token implementation until the update is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-49824
GHSA-2XF4-HG9Q-M58Q

Affected Products

Conda-Smithy