CVE-2022-41340

7.5HIGH

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

게시됨: 9/24/2022업데이트됨: 5/22/2025

설명

The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.

AI 분석AI 기반

영향받는 제품

secp256k1-js_projectsecp256k1-js

참조