GHSA-qwqc-28w3-fww6

Suggest an improvement
Source
https://github.com/advisories/GHSA-qwqc-28w3-fww6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-qwqc-28w3-fww6/GHSA-qwqc-28w3-fww6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qwqc-28w3-fww6
Aliases
Published
2019-08-23T21:42:20Z
Modified
2023-11-08T04:01:46Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Message Signature Bypass in openpgp
Details

Versions of openpgp prior to 4.2.0 are vulnerable to Message Signature Bypass. The package fails to verify that a message signature is of type text. This allows an attacker to to construct a message with a signature type that only verifies subpackets without additional input (such as standalone or timestamp). For example, an attacker that captures a standalone signature packet from a victim can construct arbitrary signed messages that would be verified correctly.

Recommendation

Upgrade to version 4.2.0 or later. If you are upgrading from a version <4.0.0 it is highly recommended to read the High-Level API Changes section of the openpgp 4.0.0 release: https://github.com/openpgpjs/openpgpjs/releases/tag/v4.0.0

Database specific
{
    "cwe_ids":  [
        "CWE-347"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-08-23T21:40:54Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / openpgp

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.2.0

Database specific

last_known_affected_version_range
"<= 4.1.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-qwqc-28w3-fww6/GHSA-qwqc-28w3-fww6.json"