Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability (Arbitrary Signature Forgery) in starkbank-ecdsa #1138

Closed
felixse opened this issue Nov 15, 2021 · 1 comment · Fixed by #1140
Closed

Vulnerability (Arbitrary Signature Forgery) in starkbank-ecdsa #1138

felixse opened this issue Nov 15, 2021 · 1 comment · Fixed by #1140
Labels
type: security known security issue

Comments

@felixse
Copy link

felixse commented Nov 15, 2021

Issue Summary

There is a new vulnerability in starkbank-ecdsa 1.3.1, please update to at least 1.3.2 to mitigate this.
More details here: https://research.nccgroup.com/2021/11/08/technical-advisory-arbitrary-signature-forgery-in-stark-bank-ecdsa-libraries/

Technical details:

  • sendgrid-csharp version: 9.24.4
@JenniferMah
Copy link
Contributor

Hi @felixse this fix will be included in the release on 11/17/21.

@shwetha-manvinkurke shwetha-manvinkurke added type: bug bug in the library type: security known security issue and removed type: bug bug in the library labels Nov 19, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: security known security issue
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants