Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jx8-q4cp-rhh6

Опубликовано: 23 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

jsrsasign: Incomplete Comparison Allows DSA Private Key Recovery via Biased Nonce Generation

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

Пакеты

Наименование

jsrsasign

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 11.1.1

11.1.1

EPSS

Процентиль: 39%
0.00476
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-1023
CWE-338

Связанные уязвимости

CVSS3: 9.1
redhat
5 месяцев назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

CVSS3: 9.1
nvd
5 месяцев назад

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

EPSS

Процентиль: 39%
0.00476
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-1023
CWE-338