robrichards/xmlseclibs is vulnerable to Observable Discrepancy
59
Medium Risk
XMLSecEnc supports RSA PKCS#1 v1.5 (rsa-1_5) key transport and returns decryption errors that distinguish padding failures from other failures, while locateKey() accepts an attacker-chosen EncryptionMethod algorithm taken from the document. Together these expose a Bleichenbacher padding oracle that can recover the transported session key and decrypt content. Distinguishable exception types and messages let the oracle be built from either the symmetric or the RSA path. The fix denies RSA-1.5 key transport by default, normalizes decryption errors, and applies RFC 3218 random session-key substitution on invalid padding.
You are affected if you are using a version that falls within the vulnerable range and you decrypt XML that uses RSA key transport from untrusted sources.
robrichards/xmlseclibs is vulnerable to Observable Discrepancy in versions 0.0.1 - 3.1.5.
Upgrade the robrichards/xmlseclibs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.