Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66030

Опубликовано: 26 нояб. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

A flaw was found in node-forge. This vulnerability allows bypass of downstream Object Identifier (OID)-based security decisions via crafting Abstract Syntax Notation One (ASN.1) structures containing Object Identifiers (OIDs) with oversized arcs, which are then decoded as smaller, trusted OIDs due to 32-bit bitwise truncation.

Отчет

This vulnerability is rated Moderate for Red Hat products. An integer overflow in the node-forge library allows for the bypass of Object Identifier (OID)-based security decisions. Attackers could craft Abstract Syntax Notation One (ASN.1) structures with oversized arcs, leading to their misinterpretation as trusted OIDs due to 32-bit bitwise truncation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatFix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleOut of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorOut of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Out of support scope
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2417384node-forge: node-forge: Integer Overflow allows OID-based security bypass

EPSS

Процентиль: 14%
0.00046
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

CVSS3: 5.3
nvd
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

msrc
4 месяца назад

node-forge ASN.1 OID Integer Truncation

CVSS3: 5.3
debian
4 месяца назад

Forge (also called `node-forge`) is a native implementation of Transpo ...

github
4 месяца назад

node-forge is vulnerable to ASN.1 OID Integer Truncation

EPSS

Процентиль: 14%
0.00046
Низкий

5.3 Medium

CVSS3