VDB
Sign up
HIGH7.5

GHSA-rh63-9qcf-83gf

Marvin Attack of RSA and RSAOAEP decryption in jsrsasign

Quick fix

GHSA-rh63-9qcf-83gf — jsrsasign: upgrade to the fixed version with the command below.

npm install jsrsasign@11.0.0

Details

### Impact RSA PKCS#1.5 or RSAOAEP ciphertexts may be decrypted by this Marvin attack vulnerability.

### Patches update to jsrsasign 11.0.0.

### Workarounds Find and replace RSA and RSAOAEP decryption with other crypto library.

### References https://people.redhat.com/~hkario/marvin/ https://github.com/kjur/jsrsasign/issues/598 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6070732 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21484

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsrsasign
Introduced in: 0Fixed in: 11.0.0
Fixnpm install jsrsasign@11.0.0

References