Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24772

Опубликовано: 18 мар. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a DigestInfo ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used. The issue has been addressed in node-forge version 1.3.0. There are currently no known workarounds.

A flaw was found in the node-forge package. This signature verification leniency allows an attacker to forge a signature.

Отчет

This flaw affects the DigestInfo ASN.1 structure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Fix deferred
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Will not fix
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-bundle-containerAffected
Red Hat 3scale API Management Platform 23scale-apicast-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2067458node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery

EPSS

Процентиль: 37%
0.00157
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 7.5
nvd
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 7.5
debian
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 7.5
github
почти 4 года назад

Improper Verification of Cryptographic Signature in node-forge

EPSS

Процентиль: 37%
0.00157
Низкий

7.5 High

CVSS3

Уязвимость CVE-2022-24772