Python Security Update (MINDBREEZE30001)

ID: MINDBREEZE30001 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 5.9 Medium 
Status: Final 
First published: March 18, 2024 
CVEs: CVE-2023-52323 

Summary

pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex

 

Hotfix Information

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 24.1 Release 
  • Mindbreeze InSpire SaaS 24.1 Release