VDB
Sign up
CRITICAL9.8

GHSA-qg3g-2mgh-33j8

Sensitive Data Exposure in msrcrypto

Quick fix

GHSA-qg3g-2mgh-33j8 — msrcrypto: upgrade to the fixed version with the command below.

npm install msrcrypto@1.4.1

Details

Versions of `msrcrypto` prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.

## Recommendation

Upgrade to version 1.4.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/msrcrypto
Introduced in: 0Fixed in: 1.4.1
Fixnpm install msrcrypto@1.4.1

References