Insecure digital certificates In node-node-forge
Description
Improper Verification of Cryptographic Signature in node-forge
Impact
RSA PKCS#1 v1.5 signature verification code is not properly checking DigestInfo for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest.
Patches
The issue has been addressed in node-forge 1.3.0.
For more information
If you have any questions or comments about this advisory:
Open an issue in forge
Email us at example email address
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 0.10.0~dfsg-3+deb11u1 | ||
npm | 1.3.0 | ||
npm | 2.1.0 | ||
rpm rhel8 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3.