CVE-2020-14966
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.
Se detectó un problema en el paquete jsrsasign por medio de 8.0.18 para Node.js. Permite una maleabilidad en las firmas ECDSA al no comprobar los desbordamientos en la longitud de una secuencia y los caracteres "0" agregados o antepuestos a un entero. Las firmas modificadas son verificadas como válidas. Esto podría tener un impacto relevante para la seguridad si una aplicación se basara en una sola firma canónica
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-06-22 CVE Reserved
- 2020-06-22 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-10-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/kjur/jsrsasign/releases/tag/8.0.17 | Release Notes | |
https://github.com/kjur/jsrsasign/releases/tag/8.0.18 | Release Notes | |
https://kjur.github.io/jsrsasign | Release Notes | |
https://security.netapp.com/advisory/ntap-20200724-0001 | Third Party Advisory | |
https://www.npmjs.com/package/jsrsasign | Product |
URL | Date | SRC |
---|---|---|
https://github.com/kjur/jsrsasign/issues/437 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jsrsasign Project Search vendor "Jsrsasign Project" | Jsrsasign Search vendor "Jsrsasign Project" for product "Jsrsasign" | <= 8.0.18 Search vendor "Jsrsasign Project" for product "Jsrsasign" and version " <= 8.0.18" | node.js |
Affected
| ||||||
Netapp Search vendor "Netapp" | Max Data Search vendor "Netapp" for product "Max Data" | - | - |
Affected
|