Vulnerability CVE-2022-41340


Published: 2022-09-24

Description:
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

 References:
https://github.com/lionello/secp256k1-js/compare/1.0.1...1.1.0
https://github.com/lionello/secp256k1-js/issues/11
https://www.npmjs.com/package/@lionello/secp256k1-js
https://github.com/lionello/secp256k1-js/commit/302800f0370b42e360a33774bb808274ac729c2e

Copyright 2024, cxsecurity.com

 

Back to Top