Логотип exploitDog
bind:CVE-2020-14968
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-14968

Количество 2

Количество 2

nvd логотип

CVE-2020-14968

больше 5 лет назад

An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as valid). An attacker can abuse this behavior in an application by creating multiple valid signatures where only one signature should exist. Also, an attacker might prepend these bytes with the goal of triggering memory corruption issues.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-q3gh-5r98-j4h3

больше 5 лет назад

RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-14968

An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as valid). An attacker can abuse this behavior in an application by creating multiple valid signatures where only one signature should exist. Also, an attacker might prepend these bytes with the goal of triggering memory corruption issues.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-q3gh-5r98-j4h3

RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign

CVSS3: 9.8
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу