CVE-2022-41340
24.09.2022, 19:15
The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signature forgery.Enginsight
Vendor | Product | Version |
---|---|---|
secp256k1-js_project | secp256k1-js | 𝑥 < 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References