Vulnerabilities/

Improper Key Verification in openpgp

Severity:
High

Description

Versions of openpgp prior to 4.2.0 are vulnerable to Improper Key Verification. The OpenPGP standard allows signature packets to have subpackets which may be hashed or unhashed. Unhashed subpackets are not cryptographically protected and cannot be trusted. The openpgp package does not verify whether a subpacket is hashed.

Recommendation

Update the openpgp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openpgp
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing