In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0736 In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. NOTE: there is no known practical attack.
Github GHSA Github GHSA GHSA-27fj-mc8w-j9wg RSA signature validation vulnerability on maleable encoded message in jsrsasign
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T22:24:59.577Z

Reserved: 2021-04-07T00:00:00

Link: CVE-2021-30246

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-07T21:15:16.153

Modified: 2024-11-21T06:03:33.820

Link: CVE-2021-30246

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses