CRITICAL9.8
GHSA-q9q6-f556-gpm7
Improper Verification of Cryptographic Signature in starkbank-ecdsa
Quick fix
GHSA-q9q6-f556-gpm7 — starkbank-ecdsa: upgrade to the fixed version with the command below.
npm install starkbank-ecdsa@1.1.3Details
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Are you affected?
Enter the version of the package you're using.