developmentil/ecdh

developmentil/ecdh

Releases3
Frequency3 years 10 months
Last Release
Stars11
Native Node.js module for ECDH and ECDSA.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.