GHSA-4grx-2x9w-596c: Marvin Attack: potential key recovery through timing sidechannels
(updated )
The Marvin Attack is a timing sidechannel vulnerability which allows performing RSA decryption and signing operations as an attacker with the ability to observe only the time of the decryption operation performed withthe private key.
A recent survey of RSA implementations found that the Rust rsa
crate is one of many implementations vulnerable to this attack.
No fixed version is available at this time.
References
Detect and mitigate GHSA-4grx-2x9w-596c with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →