← Zuruck zu CVEs
CVE-2020-14968
CRITICAL9.8
Beschreibung
An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as valid). An attacker can abuse this behavior in an application by creating multiple valid signatures where only one signature should exist. Also, an attacker might prepend these bytes with the goal of triggering memory corruption issues.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/22/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
jsrsasign_project:jsrsasignnetapp:max_data
Schwachen (CWE)
CWE-119
Referenzen
https://github.com/kjur/jsrsasign/issues/438(cve@mitre.org)
https://github.com/kjur/jsrsasign/releases/tag/8.0.17(cve@mitre.org)
https://github.com/kjur/jsrsasign/releases/tag/8.0.18(cve@mitre.org)
https://kjur.github.io/jsrsasign/(cve@mitre.org)
https://security.netapp.com/advisory/ntap-20200724-0001/(cve@mitre.org)
https://www.npmjs.com/package/jsrsasign(cve@mitre.org)
https://github.com/kjur/jsrsasign/issues/438(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/kjur/jsrsasign/releases/tag/8.0.17(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/kjur/jsrsasign/releases/tag/8.0.18(af854a3a-2127-422b-91ae-364da2661108)
https://kjur.github.io/jsrsasign/(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20200724-0001/(af854a3a-2127-422b-91ae-364da2661108)
https://www.npmjs.com/package/jsrsasign(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.