Oracle Padding Attack in conda-smithy by Anaconda, Inc.
CVE-2025-49824
1.7LOW
What is CVE-2025-49824?
The conda-smithy tool, used for integrating conda recipes with CI service configurations, was found to be vulnerable to an Oracle Padding Attack prior to version 3.47.1. This security issue arises from the implementation of an outdated padding scheme during RSA encryption, allowing malicious actors with access to an oracle system to isolate and retrieve plaintext data by submitting modified ciphertexts and analyzing the generated responses. This vulnerability has been remedied in the latest release, ensuring enhanced security for users.
Affected Version(s)
conda-smithy < 3.47.1
