QID 982924

QID 982924: Nodejs (npm) Security Update for elliptic (GHSA-r9p9-mrjm-926w)

The npm package `elliptic` before version 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the derive function actually exists on the secp256k1 curve. This results in the potential for the private key used in this implementation to be revealed after a number of ECDH operations are performed.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-r9p9-mrjm-926w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982924

    Software Advisories
    Advisory ID Software Component Link
    GHSA-r9p9-mrjm-926w elliptic URL Logo github.com/advisories/GHSA-r9p9-mrjm-926w