HIGH
GHSA-9wx7-jrvc-28mm
Signature verification vulnerability in Stark Bank ecdsa libraries
Quick fix
GHSA-9wx7-jrvc-28mm — starkbank-ecdsa: upgrade to the fixed version with the command below.
pip install --upgrade 'starkbank-ecdsa>=2.0.1'Details
An attacker can forge signatures on arbitrary messages that will verify for any public key. This may allow attackers to authenticate as any user within the Stark Bank platform, and bypass signature verification needed to perform operations on the platform, such as send payments and transfer funds. Additionally, the ability for attackers to forge signatures may impact other users and projects using these libraries in different and unforeseen ways.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/starkbank-ecdsa
Introduced in:
0Fixed in: 2.0.1Fix
pip install --upgrade 'starkbank-ecdsa>=2.0.1'Maven/com.starkbank:ecdsa-java
Introduced in:
1.0.0Fixed in: 1.0.1Fix
# pom.xml: bump <version>1.0.1</version> for com.starkbank:ecdsa-javaNuGet/starkbank-ecdsa
Introduced in:
1.3.1Fixed in: 1.3.2Fix
dotnet add package starkbank-ecdsa --version 1.3.2References
- https://github.com/starkbank/ecdsa-python/commit/d136170666e9510eb63c2572551805807bd4c17f[WEB]
- https://github.com/starkbank/ecdsa-dotnet[WEB]
- https://github.com/starkbank/ecdsa-java[WEB]
- https://github.com/starkbank/ecdsa-node[WEB]
- https://github.com/starkbank/ecdsa-python[PACKAGE]
- https://github.com/starkbank/ecdsa-python/compare/v2.0.0...v2.0.1[WEB]
- https://github.com/starkbank/ecdsa-python/releases/tag/v2.0.1[WEB]
- https://research.nccgroup.com/2021/11/08/technical-advisory-arbitrary-signature-forgery-in-stark-bank-ecdsa-libraries[WEB]