7.4
CWE
385
Advisory Published
CVE Published
Updated

CVE-2023-46809

First published: Fri Feb 16 2024(Updated: )

A vulnerability in the privateDecrypt() API of the crypto library, allowed a covert timing side-channel during PKCS#1 v1.5 padding error handling. The vulnerability revealed significant timing differences in decryption for valid and invalid ciphertexts. This poses a serious threat as attackers could remotely exploit the vulnerability to decrypt captured RSA ciphertexts or forge signatures, especially in scenarios involving API endpoints processing Json Web Encryption messages. This vulnerability affects all users in all active release lines: 18.x, 20.x, and 21.x.

Credit: support@hackerone.com

Affected SoftwareAffected VersionHow to fix
redhat/node<18.19.1
18.19.1
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2023-46809?

    CVE-2023-46809 is considered a serious vulnerability that can lead to timing side-channel attacks during PKCS#1 v1.5 padding error handling.

  • How do I fix CVE-2023-46809?

    To fix CVE-2023-46809, update the affected software to the latest patched versions provided by the vendor.

  • Which software does CVE-2023-46809 affect?

    CVE-2023-46809 affects Node.js and different versions of IBM Cognos Analytics.

  • What type of attack can be performed using CVE-2023-46809?

    CVE-2023-46809 allows attackers to exploit timing differences in decryption processes, potentially revealing sensitive data.

  • Is there a patch available for CVE-2023-46809?

    Yes, patches are available for the affected versions of both Node.js and IBM Cognos Analytics.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203