VDB
Sign up
MEDIUM

GHSA-h87q-g2wp-47pj

Signatures are mistakenly recognized to be valid in jsrsasign

Quick fix

GHSA-h87q-g2wp-47pj — jsrsasign: upgrade to the fixed version with the command below.

npm install jsrsasign@10.2.0

Details

In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsrsasign
Introduced in: 0Fixed in: 10.2.0
Fixnpm install jsrsasign@10.2.0

References