VDB
Sign up
CRITICAL9.1

GHSA-27fj-mc8w-j9wg

RSA signature validation vulnerability on maleable encoded message in jsrsasign

Quick fix

GHSA-27fj-mc8w-j9wg — jsrsasign: upgrade to the fixed version with the command below.

npm install jsrsasign@10.2.0

Details

### Impact Vulnerable jsrsasign will accept RSA signature with improper PKCS#1.5 padding. Decoded RSA signature value consists following form: `01(ff...(8 or more ffs)...ff)00[ASN.1 OF DigestInfo]` Its byte length must be the same as RSA key length, however such checking was not sufficient.

To make crafted message for practical attack is very hard.

### Patches Users validating RSA signature should upgrade to 10.2.0 or later.

### Workarounds There is no workaround. Not to use RSA signature validation in jsrsasign.

### ACKNOWLEDGEMENT Thanks to Daniel Yahyazadeh @yahyazadeh for reporting and analyzing this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsrsasign
Introduced in: 0Fixed in: 10.2.0
Fixnpm install jsrsasign@10.2.0

References