CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2020-14966 — HIGH severity vulnerability | Release Alert
CVE-2020-14966
7.5
HIGHCVSS v3
Published
June 22, 2020
CVSS v2
5 MEDIUM
Affected
2 projects
Assigned by
MITRE
Severity scale
010
Description
An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.
GitHubCAUTION: END OF SUPPORT ON 3 JUN 2026. The 'jsrsasign' (RSA-Sign JavaScript Library) is an opensource free cryptography library supporting RSA/RSAPSS/ECDSA/DSA signing/validation, ASN.1, PKCS#1/5/8 private/public key, X.509 certificate, CRL, OCSP, CMS SignedData, TimeStamp, CAdES and JSON Web Signature/Token in pure JavaScript.