Описание
In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.
Ссылки
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- Release NotesThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.1.13 (включая)
cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 42%
0.002
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 9.1
github
почти 5 лет назад
RSA signature validation vulnerability on maleable encoded message in jsrsasign
EPSS
Процентиль: 42%
0.002
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-347