Description
Versions of msrcrypto prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package’s Elliptic Curve Cryptography (ECC) implementation may leak information about a server’s private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability.
Recommendation
Update the msrcrypto package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.1
- Patched version(s): 1.4.1
References
- GHSA-qg3g-2mgh-33j8
- portal.msrc.microsoft.com
- www.npmjs.com
- www.securityfocus.com
- www.securitytracker.com
- CVE-2018-8319
- CWE-682
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Sensitive data exposure in NATS - CVE-2020-26149
- Sensitive data exposure in NATS - nats - CVE-2020-26149
- Converse.js Exposure of Sensitive Information - CVE-2018-6591
- @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - CVE-2026-8766
You might also like:
- Tags:
- npm
- msrcrypto
Anything's wrong? Let us know Last updated on January 09, 2023


