Vulnerabilities/

secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery

Severity:
High

Description

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

Recommendation

Update the @lionello/secp256k1-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@lionello/secp256k1-js
Anything's wrong? Let us know Last updated on January 28, 2023

This issue is available in SmartScanner Professional

See Pricing