#VU65749 Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24771
Published: July 25, 2022
node-forge
Synex Technologies
Description
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to a improper signature verification when checking the digestAlgorithm structure. A remote unauthenticated attacker can use a specially-crafted structure to steal padding bytes and use unchecked portion of the PKCS#1 encoded message to exploit this vulnerability and forge a signature when a low public exponent is being used.