Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-42460
HistoryAug 02, 2024 - 12:00 a.m.

CVE-2024-42460

2024-08-0200:00:00
mitre
github.com
3
elliptic package node.js ecdsa signature malleability

AI Score

6.8

Confidence

Low

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial

In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:elliptic_project:elliptic:6.5.6:*:*:*:*:node.js:*:*"
    ],
    "vendor": "elliptic_project",
    "product": "elliptic",
    "versions": [
      {
        "status": "affected",
        "version": "6.5.6"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

poc

Automatable

yes

Technical Impact

partial