Lack of data validation - Token In com.starkbank.ellipticcurve:starkbank-ecdsa
Description
Improper Verification of Cryptographic Signature in starkbank-ecdsa The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.0.1 | ||
maven | 1.0.1 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4.