Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-42461

Опубликовано: 02 авг. 2024
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

A flaw was found in the Elliptic package for Node.js. ECDSA signatures encoded in BER format are improperly validated, allowing leading zeros to be added to the signature without invalidating it, resulting in confidentiality issues.

Отчет

This vulnerability was found in the elliptic npm package, it is an Improper Verification of Cryptographic Signature that occurs because the library accepts non-strictly BER-encoded signatures.This allows an attacker to create another valid signature for the same message, which may cause issues in systems that rely on unique signatures for identifying transactions.The overall impact on confidentiality is low.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-rhel9-operatorNot affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-shared-resource-webhook-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Not affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-webhook-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2302460elliptic: nodejs/elliptic: ECDSA implementation malleability due to BER-enconded signatures being allowed

EPSS

Процентиль: 47%
0.00617
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 лет назад

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

CVSS3: 9.1
nvd
около 2 лет назад

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

CVSS3: 9.1
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 9.1
debian
около 2 лет назад

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleabilit ...

CVSS3: 5.3
github
около 2 лет назад

Elliptic allows BER-encoded signatures

EPSS

Процентиль: 47%
0.00617
Низкий

5.3 Medium

CVSS3