Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r2c-g63r-vccr

Опубликовано: 18 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Verification of Cryptographic Signature in node-forge

Impact

RSA PKCS#1 v1.5 signature verification code is not properly checking DigestInfo for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest.

Patches

The issue has been addressed in node-forge 1.3.0.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

node-forge

npm
Затронутые версииВерсия исправления

< 1.3.0

1.3.0

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 5.3
redhat
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 5.3
nvd
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 5.3
debian
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-347