Description
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.
Recommendation
Update the msrcrypto package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.5.8
- Patched version(s): 1.5.8
References
Related Issues
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Expo on iOS is insecure due incorrect security attribute application - CVE-2020-24653
- Insecure serialization leading to RCE in serialize-javascript - CVE-2020-7660
- Uncontrolled Resource Consumption in fun-map - CVE-2020-7644
You might also like:
- Tags:
- npm
- msrcrypto
Anything's wrong? Let us know Last updated on February 01, 2023


