GHSA-qwqc-28w3-fww6

    Dashboard / Vulnerabilities / GHSA-qwqc-28w3-fww6

    GHSA-qwqc-28w3-fww6

    Published: 23 Aug 2019Last Modified: 8 Nov 2023
    Aliases:

    Summary: Message Signature Bypass in openpgp

    Details: Versions of `openpgp` prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type `text`. This allows an attacker to to construct a message with a signature type that only verifies subpackets without additional input (such as `standalone` or `timestamp`). For example, an attacker that captures a `standalone` signature packet from a victim can construct arbitrary signed messages that would be verified correctly. ## Recommendation Upgrade to version 4.2.0 or later. If you are upgrading from a version <4.0.0 it is highly recommended to read the `High-Level API Changes` section of the `openpgp` 4.0.0 release: https://github.com/openpgpjs/openpgpjs/releases/tag/v4.0.0

    Affected packages

    Package

    Name: openpgp

    Purl: pkg:npm/openpgp

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -4.2.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qwqc-28w3-fww6 | CVE-DB