Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34763
HistoryMar 21, 2022 - 11:00 a.m.

Improper Verification Of Signature

2022-03-2111:00:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
improper verification
cryptographic signature
node-forge software
vulnerability
signature forge attack

EPSS

0.001

Percentile

36.5%

node-forge is vulnerable to improper verification of the cryptographic signature. The vulnerability exists due to improper signature verification of tailing garbage bytes in the rsa.js file allowing an attacker to execute a signature forge attack