VDB
Sign up
HIGH

GHSA-9wx7-jrvc-28mm

Signature verification vulnerability in Stark Bank ecdsa libraries

Quick fix

GHSA-9wx7-jrvc-28mm — starkbank-ecdsa: upgrade to the fixed version with the command below.

pip install --upgrade 'starkbank-ecdsa>=2.0.1'

Details

An attacker can forge signatures on arbitrary messages that will verify for any public key. This may allow attackers to authenticate as any user within the Stark Bank platform, and bypass signature verification needed to perform operations on the platform, such as send payments and transfer funds. Additionally, the ability for attackers to forge signatures may impact other users and projects using these libraries in different and unforeseen ways.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/starkbank-ecdsa
Introduced in: 0Fixed in: 2.0.1
Fixpip install --upgrade 'starkbank-ecdsa>=2.0.1'
Maven/com.starkbank:ecdsa-java
Introduced in: 1.0.0Fixed in: 1.0.1
Fix# pom.xml: bump <version>1.0.1</version> for com.starkbank:ecdsa-java
NuGet/starkbank-ecdsa
Introduced in: 1.3.1Fixed in: 1.3.2
Fixdotnet add package starkbank-ecdsa --version 1.3.2
npm/starkbank-ecdsa
Introduced in: 1.1.2Fixed in: 1.1.3
Fixnpm install starkbank-ecdsa@1.1.3

References