jsrsasign Project jsrsasign 10.5.2 for Node.js

CPE Details

jsrsasign Project jsrsasign 10.5.2 for Node.js
10.5.2
2022-07-11
14h20 +00:00
2022-07-12
11h08 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:jsrsasign_project:jsrsasign:10.5.2:*:*:*:*:node.js:*:*

Informations

Vendor

jsrsasign_project

Product

jsrsasign

Version

10.5.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-21484 2024-01-22 05h00 +00:00 Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.
7.5
Haute
CVE-2022-25898 2022-07-01 20h02 +00:00 The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT signature if it has Base64URL and dot safe string before executing JWS.verify() or JWS.verifyJWT() method.
9.8
Critique