CVE-2024-45191
MEDIUMDescription
An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Is your site exposed to CVE-2024-45191?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| matrix | olm |
References
Frequently Asked Questions
What is CVE-2024-45191? +
How severe is CVE-2024-45191? +
What products are affected by CVE-2024-45191? +
How do I check if I'm vulnerable to CVE-2024-45191? +
Related Vulnerabilities
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash …
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference …
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate …
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash …
PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implements multiplication via …
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the …