#VU65780 Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24773
Published: July 26, 2022
node-forge
Synex Technologies
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. A remote unauthenticated attacker can get a successful verification with signatures that contain invalid structures but a valid digest