Vulnerabilities/

Cleartext Signed Message Signature Spoofing in openpgp

Severity:
Medium

Description

OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools:

These messages typically contain a “Hash: …” header declaring the hash algorithm used to compute the signature digest. OpenPGP.js up to v5.9.0 ignored any data preceding the “Hash: …

Recommendation

Update the openpgp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openpgp
Anything's wrong? Let us know Last updated on November 06, 2023

This issue is available in SmartScanner Professional

See Pricing