Vulnerabilities/

RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign

Severity:
High

Description

Jsrsasign can verify RSA-PSS signature which value can expressed as BigInteger. When there is a valid RSA-PSS signature value, this vulnerability is also accept value with prepending zeros as a valid signature.

Recommendation

Update the jsrsasign package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsrsasign
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing