GHSA-qg3g-2mgh-33j8
Dashboard / Vulnerabilities / GHSA-qg3g-2mgh-33j8
Summary: Sensitive Data Exposure in msrcrypto
Details: Versions of `msrcrypto` prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability. ## Recommendation Upgrade to version 1.4.1 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-8319, https://github.com/advisories/GHSA-qg3g-2mgh-33j8, https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8319, https://www.npmjs.com/advisories/1112, http://www.securityfocus.com/bid/104655, http://www.securitytracker.com/id/1041268
Affected packages
Package
Name: msrcrypto
Purl: pkg:npm/msrcrypto
Affected ranges
Type: SEMVER
Events:
