Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jx8-q4cp-rhh6

Опубликовано: 23 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

Пакеты

Наименование

jsrsasign

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 11.1.1

11.1.1

EPSS

Процентиль: 11%
0.00037
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-1023

Связанные уязвимости

CVSS3: 9.1
redhat
17 дней назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
nvd
17 дней назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

EPSS

Процентиль: 11%
0.00037
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-1023