Improper Verification of Cryptographic Signature in `node-forge`
Moderate severity
GitHub Reviewed
Published
Mar 17, 2022
in
digitalbazaar/forge
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 18, 2022
Published to the GitHub Advisory Database
Mar 18, 2022
Reviewed
Mar 18, 2022
Last updated
Jan 27, 2023
Impact
RSA PKCS#1 v1.5 signature verification code is not properly checking
DigestInfo
for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest.Patches
The issue has been addressed in
node-forge
1.3.0
.For more information
If you have any questions or comments about this advisory:
References