generated from Richienb/node-module-boilerplate
-
-
Notifications
You must be signed in to change notification settings - Fork 32
Open
Description
Package Manager: npm
Vulnerable module: elliptic
Introduced through: [email protected] and others
Detailed paths
[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
Overview
elliptic is a fast elliptic-curve cryptography implementation in plain javascript.
Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature due to a missing signature length check in the EDDSA signature process. An attacker can manipulate the signature by appending or removing zero-valued bytes.
Remediation
Upgrade elliptic to version 6.6.1 or higher.
stephanebouget, afiller and hans-luciad
Metadata
Metadata
Assignees
Labels
No labels