High severity7.4NVD Advisory· Published Jan 23, 2024· Updated Jun 17, 2026
CVE-2024-23342
CVE-2024-23342
Description
The ecdsa PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack. As of time of publication, no known patched version exists.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ecdsaPyPI | >= 0 | — |
Affected products
8- osv-coords6 versionspkg:apk/chainguard/airflow-3pkg:apk/chainguard/awxpkg:apk/chainguard/open-webuipkg:apk/wolfi/airflow-3pkg:apk/wolfi/open-webuipkg:pypi/ecdsa
< 3.2.2-r0+ 5 more
- (no CPE)range: < 3.2.2-r0
- (no CPE)range: < 24.6.1-r33
- (no CPE)range: < 0.11.0-r0
- (no CPE)range: < 3.2.2-r0
- (no CPE)range: < 0.11.0-r0
- (no CPE)range: >= 0
- Range: <= 0.18.0
Patches
Vulnerability mechanics
References
8- github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-wj6h-64fc-37mpnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-wj6h-64fc-37mpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23342ghsaADVISORY
- github.com/tlsfuzzer/python-ecdsa/blob/master/SECURITY.mdnvdProductWEB
- minerva.crocs.fi.muni.czghsaWEB
- minerva.crocs.fi.muni.cznvdTechnical Description
- securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-pythonghsaWEB
- securitypitfalls.wordpress.com/2018/08/03/constant-time-compare-in-python/nvdTechnical Description
News mentions
0No linked articles in our index yet.