Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg3g-2mgh-33j8

Опубликовано: 10 сент. 2018
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Sensitive Data Exposure in msrcrypto

Versions of msrcrypto prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.

Recommendation

Upgrade to version 1.4.1 or later.

Пакеты

Наименование

msrcrypto

npm
Затронутые версииВерсия исправления

< 1.4.1

1.4.1

EPSS

Процентиль: 91%
0.07396
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library.

msrc
около 7 лет назад

MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability

EPSS

Процентиль: 91%
0.07396
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-682