Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34767
HistoryMar 21, 2022 - 12:01 p.m.

Insecure Cryptography

2022-03-2112:01:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
insecure cryptography
digestinfo vulnerability
rsa.js file
attacker actions

EPSS

0.001

Percentile

35.9%

node-forge improperly verifies cryptographic signatures. The vulnerability exists through improper verification of DigestInfo in the rsa.js file allowing to validate the signature in an invalid structure which allows an attacker to perform unwanted actions.