Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34759
HistoryMar 21, 2022 - 9:26 a.m.

Improper Signature Verification

2022-03-2109:26:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27
signature verification
remote attackers
digital certificates

EPSS

0.001

Percentile

26.7%

node-forge uses improper signature verification. Leniency in checking the digest algorithm structure allows remote attackers to specifically craft a structure that steals padding bytes and uses unchecked portion of the PKCS#1 encoded message to forge a signature when a low public exponent is being used.