You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Forge (also called node-forge) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses unchecked portion of the PKCS#1 encoded message to forge a signature when a low public exponent is being used. The issue has been addressed in node-forge version 1.3.0. There are currently no known workarounds.
HIGH Vulnerable Package issue exists @ node-forge in branch main
Description
Forge (also called
node-forge
) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses unchecked portion of the PKCS#1 encoded message to forge a signature when a low public exponent is being used. The issue has been addressed innode-forge
version 1.3.0. There are currently no known workarounds.HIGH Vulnerable Package issue exists @ node-forge in branch main
Vulnerability ID: CVE-2022-24771
Package Name: node-forge
Severity: HIGH
CVSS Score: 7.5
Publish Date: 2022-03-18T14:15:00
Current Package Version: 0.10.0
Remediation Upgrade Recommendation: 1.3.0
Link To SCA
Reference – NVD link
The text was updated successfully, but these errors were encountered: