CVE-2024-21484 – jsrsasign
Package
Manager: npm
Name: jsrsasign
Vulnerable Version: >=0 <11.0.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L
EPSS: 0.00248 pctl0.47893
Details
Marvin Attack of RSA and RSAOAEP decryption in jsrsasign ### Impact RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability. ### Patches update to jsrsasign 11.0.0. ### Workarounds Find and replace RSA and RSAOAEP decryption with other crypto library. ### References https://people.redhat.com/~hkario/marvin/ https://github.com/kjur/jsrsasign/issues/598 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484
Metadata
Created: 2024-01-19T15:06:07Z
Modified: 2024-02-27T19:23:58Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-rh63-9qcf-83gf/GHSA-rh63-9qcf-83gf.json
CWE IDs: ["CWE-203"]
Alternative ID: GHSA-rh63-9qcf-83gf
Finding: F026
Auto approve: 1