OSV 1.4.0 · github-reviewed · 修改于 2021-11-15 22:44
发布时间
2021-11-11 04:58
GitHub 审查时间
2021-11-11 02:27
NVD 发布时间
2021-11-10 06:15
源文件
advisories/github-reviewed/2021/11/GHSA-q9q6-f556-gpm7/GHSA-q9q6-f556-gpm7.json
The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.