QID 980935
QID 980935: Nodejs (npm) Security Update for msrcrypto (GHSA-qg3g-2mgh-33j8)
Versions of `msrcrypto` prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.
## Recommendation
Upgrade to version 1.4.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qg3g-2mgh-33j8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-qg3g-2mgh-33j8 -
github.com/advisories/GHSA-qg3g-2mgh-33j8
CVEs related to QID 980935
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qg3g-2mgh-33j8 | msrcrypto |
|