CVE-2021-30246
Summary
| CVE | CVE-2021-30246 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-07 21:15:00 UTC |
| Updated | 2021-04-14 16:09:00 UTC |
| Description | In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release add non-ascii BMPString support · kjur/jsrsasign · GitHub |
MISC |
github.com |
|
| jsrsasign - cryptography library in JavaScript |
MISC |
kjur.github.io |
|
| Leniency in parsing block type byte and padding bytes for PKCS#1 v1.5 signature verification · Issue #478 · kjur/jsrsasign · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982723 Nodejs (npm) Security Update for jsrsasign (GHSA-27fj-mc8w-j9wg)