QID 980155
QID 980155: Nodejs (npm) Security Update for starkbank-ecdsa (GHSA-q9q6-f556-gpm7)
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q9q6-f556-gpm7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-q9q6-f556-gpm7 -
github.com/advisories/GHSA-q9q6-f556-gpm7
CVEs related to QID 980155
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q9q6-f556-gpm7 | starkbank-ecdsa |
|