Description
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.
Recommendation
Update the msrcrypto package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.5.8
- Patched version(s): 1.5.8
References
Could your website be exposed too?
SmartScanner can check your website for Incorrect Calculation in the MSR JavaScript Cryptography Library and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Input Validation in Google Closure Library - CVE-2020-8910
- Expo on iOS is insecure due incorrect security attribute application - CVE-2020-24653
- Insecure serialization leading to RCE in serialize-javascript - CVE-2020-7660
- Uncontrolled Resource Consumption in fun-map - CVE-2020-7644


