{"id":"CVE-2021-24117","details":"In Apache Teaclave Rust SGX SDK 1.1.3, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.","modified":"2026-08-27T08:40:31.320756Z","published":"2021-07-14T14:15:08.810Z","references":[{"type":"ADVISORY","url":"https://docs.rs/crate/sgx_tstd/1.1.1"},{"type":"FIX","url":"https://github.com/UzL-ITS/util-lookup/blob/main/cve-vulnerability-publication.md"},{"type":"FIX","url":"https://github.com/dingelish/rust-base64/commit/a554b7ae880553db6dde8a387101a093911d5b2a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/teaclave-sgx-sdk","events":[{"introduced":"a6a172e652b4db4eaa17e4faa078fda8922abdd0"},{"last_affected":"a6a172e652b4db4eaa17e4faa078fda8922abdd0"}],"database_specific":{"cpe":"cpe:2.3:a:apache:teaclave_sgx_sdk:1.1.3:*:*:*:*:rust:*:*","extracted_events":[{"introduced":"1.1.3"},{"last_affected":"1.1.3"}],"source":"CPE_STRING"}}],"versions":["1.1.3","v1.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24117.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/dingelish/rust-base64","events":[{"introduced":"0"},{"fixed":"a554b7ae880553db6dde8a387101a093911d5b2a"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.13.0","v0.12.3","v0.12.2","v0.12.1","v0.12.0","v0.11.0","v0.10.1","v0.10.0","v0.9.3","v0.9.1","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.2","v0.5.1","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.2.1","v0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24117.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}