Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9p9-mrjm-926w

Опубликовано: 08 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Elliptic Uses a Broken or Risky Cryptographic Algorithm

The npm package elliptic before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

Пакеты

Наименование

elliptic

npm
Затронутые версииВерсия исправления

< 6.5.4

6.5.4

EPSS

Процентиль: 64%
0.00473
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

CVSS3: 6.8
nvd
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

CVSS3: 6.8
debian
около 5 лет назад

The package elliptic before 6.5.4 are vulnerable to Cryptographic Issu ...

EPSS

Процентиль: 64%
0.00473
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-327