#VU98513 Input validation error in elliptic - CVE-2024-48949
Published: October 14, 2024
elliptic
indutny
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input within the verify() function in lib/elliptic/eddsa/index.js. A remote attacker can send specially crafted input to the application and bypass implemented security restrictions.