Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8q8-93cx-6h7r

Опубликовано: 23 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 8.7

Описание

jsrsasign: Missing cryptographic validation during DSA signing enables private key extraction

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

Пакеты

Наименование

jsrsasign

npm
Затронутые версииВерсия исправления

< 11.1.1

11.1.1

EPSS

Процентиль: 3%
0.00015
Низкий

8.8 High

CVSS4

8.7 High

CVSS3

Дефекты

CWE-325

Связанные уязвимости

CVSS3: 8.7
redhat
17 дней назад

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

CVSS3: 8.7
nvd
17 дней назад

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

EPSS

Процентиль: 3%
0.00015
Низкий

8.8 High

CVSS4

8.7 High

CVSS3

Дефекты

CWE-325