Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24773

Опубликовано: 18 мар. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check DigestInfo for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in node-forge version 1.3.0. There are currently no known workarounds.

A flaw was found in the node-forge library when verifying the signature on the ASN.1 structure in RSA PKCS#1 v1.5. This flaw allows an attacker to obtain successful verification for invalid DigestInfo structure, affecting the integrity of the attacked resource.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Fix deferred
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-api-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-db-migration-rhel8Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Will not fix
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-bundle-containerAffected
Red Hat 3scale API Management Platform 23scale-apicast-operator-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2067461node-forge: Signature verification leniency in checking `DigestInfo` structure

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 5.3
nvd
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.

CVSS3: 5.3
debian
почти 4 года назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

CVSS3: 5.3
github
почти 4 года назад

Improper Verification of Cryptographic Signature in `node-forge`

EPSS

Процентиль: 32%
0.00126
Низкий

5.3 Medium

CVSS3