VDB
Sign up
HIGH7.5

GHSA-qwqc-28w3-fww6

Message Signature Bypass in openpgp

Quick fix

GHSA-qwqc-28w3-fww6 — openpgp: upgrade to the fixed version with the command below.

npm install openpgp@4.2.0

Details

Versions of `openpgp` prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type `text`. This allows an attacker to to construct a message with a signature type that only verifies subpackets without additional input (such as `standalone` or `timestamp`). For example, an attacker that captures a `standalone` signature packet from a victim can construct arbitrary signed messages that would be verified correctly.

## Recommendation

Upgrade to version 4.2.0 or later. If you are upgrading from a version <4.0.0 it is highly recommended to read the `High-Level API Changes` section of the `openpgp` 4.0.0 release: https://github.com/openpgpjs/openpgpjs/releases/tag/v4.0.0

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/openpgp
Introduced in: 0Fixed in: 4.2.0
Fixnpm install openpgp@4.2.0

References