GHSA-qg3g-2mgh-33j8

    Dashboard / Vulnerabilities / GHSA-qg3g-2mgh-33j8

    GHSA-qg3g-2mgh-33j8

    Published: 10 Sept 2018Last Modified: 8 Nov 2023
    Aliases:

    Summary: Sensitive Data Exposure in msrcrypto

    Details: Versions of `msrcrypto` prior to 1.4.1 are vulnerable to Sensitive Data Exposure. The package's Elliptic Curve Cryptography (ECC) implementation may leak information about a server's private ECC key. It can also allow attackers to craft invalid ECDSA signatures that pass as valid. There is no published proof-of-concept for this vulnerability. ## Recommendation Upgrade to version 1.4.1 or later.

    Affected packages

    Package

    Name: msrcrypto

    Purl: pkg:npm/msrcrypto

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High