Oracle Padding Attack in conda-smithy by Anaconda, Inc.
CVE-2025-49824

1.7LOW

Key Information:

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49824?

The conda-smithy tool, used for integrating conda recipes with CI service configurations, was found to be vulnerable to an Oracle Padding Attack prior to version 3.47.1. This security issue arises from the implementation of an outdated padding scheme during RSA encryption, allowing malicious actors with access to an oracle system to isolate and retrieve plaintext data by submitting modified ciphertexts and analyzing the generated responses. This vulnerability has been remedied in the latest release, ensuring enhanced security for users.

Affected Version(s)

conda-smithy < 3.47.1

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.