QID 981667
QID 981667: Nodejs (npm) Security Update for openpgp (GHSA-qwqc-28w3-fww6)
Versions of `openpgp` prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type `text`. This allows an attacker to to construct a message with a signature type that only verifies subpackets without additional input (such as `standalone` or `timestamp`). For example, an attacker that captures a `standalone` signature packet from a victim can construct arbitrary signed messages that would be verified correctly.
## Recommendation
Upgrade to version 4.2.0 or later.
If you are upgrading from a version <4.0.0 it is highly recommended to read the `High-Level API Changes` section of the `openpgp` 4.0.0 release: https://github.com/openpgpjs/openpgpjs/releases/tag/v4.0.0
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
- GHSA-qwqc-28w3-fww6 -
github.com/advisories/GHSA-qwqc-28w3-fww6
CVEs related to QID 981667
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qwqc-28w3-fww6 | openpgp |
|