CVE-2024-48949

EUVD-2024-2924
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
indutnyelliptic
𝑥
< 6.5.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-elliptic
bookworm
no-dsa
bullseye
postponed
forky
6.6.1+dfsg-1
fixed
sid
6.6.1+dfsg-1
fixed
trixie
6.6.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-elliptic
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
not-affected
questing
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
aws-cli
suse enterprise sap 15 SP4
1.33.26-150400.34.7.1
fixed
suse enterprise sap 15 SP5
1.33.26-150400.34.7.1
fixed
suse enterprise sap 15 SP6
1.33.26-150400.34.7.1
fixed
suse enterprise server 15 SP4
1.33.26-150400.34.7.1
fixed
suse enterprise server 15 SP5
1.33.26-150400.34.7.1
fixed
suse enterprise server 15 SP6
1.33.26-150400.34.7.1
fixed
pgadmin4
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed
pgadmin4-doc
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed
python311-boto3
suse enterprise desktop 15 SP7
1.34.138-150400.27.7.1
fixed
suse enterprise sap 15 SP4
1.34.138-150400.27.7.1
fixed
suse enterprise sap 15 SP5
1.34.138-150400.27.7.1
fixed
suse enterprise sap 15 SP6
1.34.138-150400.27.7.1
fixed
suse enterprise sap 15 SP7
1.34.138-150400.27.7.1
fixed
suse enterprise server 15 SP4
1.34.138-150400.27.7.1
fixed
suse enterprise server 15 SP5
1.34.138-150400.27.7.1
fixed
suse enterprise server 15 SP6
1.34.138-150400.27.7.1
fixed
suse enterprise server 15 SP7
1.34.138-150400.27.7.1
fixed
python311-botocore
suse enterprise desktop 15 SP7
1.34.144-150400.41.7.1
fixed
suse enterprise sap 15 SP4
1.34.144-150400.41.7.1
fixed
suse enterprise sap 15 SP5
1.34.144-150400.41.7.1
fixed
suse enterprise sap 15 SP6
1.34.144-150400.41.7.1
fixed
suse enterprise sap 15 SP7
1.34.144-150400.41.7.1
fixed
suse enterprise server 15 SP4
1.34.144-150400.41.7.1
fixed
suse enterprise server 15 SP5
1.34.144-150400.41.7.1
fixed
suse enterprise server 15 SP6
1.34.144-150400.41.7.1
fixed
suse enterprise server 15 SP7
1.34.144-150400.41.7.1
fixed
python311-coverage
suse enterprise desktop 15 SP6
7.6.10-150400.12.6.1
fixed
suse enterprise desktop 15 SP7
7.6.10-150400.12.6.1
fixed
suse enterprise sap 15 SP6
7.6.10-150400.12.6.1
fixed
suse enterprise sap 15 SP7
7.6.10-150400.12.6.1
fixed
suse enterprise server 15 SP4
7.6.10-150400.12.6.1
fixed
suse enterprise server 15 SP5
7.6.10-150400.12.6.1
fixed
suse enterprise server 15 SP6
7.6.10-150400.12.6.1
fixed
suse enterprise server 15 SP7
7.6.10-150400.12.6.1
fixed
python311-pluggy
suse enterprise desktop 15 SP6
1.5.0-150400.14.10.1
fixed
suse enterprise desktop 15 SP7
1.5.0-150400.14.10.1
fixed
suse enterprise sap 15 SP6
1.5.0-150400.14.10.1
fixed
suse enterprise sap 15 SP7
1.5.0-150400.14.10.1
fixed
suse enterprise server 15 SP4
1.5.0-150400.14.10.1
fixed
suse enterprise server 15 SP5
1.5.0-150400.14.10.1
fixed
suse enterprise server 15 SP6
1.5.0-150400.14.10.1
fixed
suse enterprise server 15 SP7
1.5.0-150400.14.10.1
fixed
python311-pytest
suse enterprise desktop 15 SP6
8.3.5-150400.3.9.1
fixed
suse enterprise desktop 15 SP7
8.3.5-150400.3.9.1
fixed
suse enterprise sap 15 SP6
8.3.5-150400.3.9.1
fixed
suse enterprise sap 15 SP7
8.3.5-150400.3.9.1
fixed
suse enterprise server 15 SP4
8.3.5-150400.3.9.1
fixed
suse enterprise server 15 SP5
8.3.5-150400.3.9.1
fixed
suse enterprise server 15 SP6
8.3.5-150400.3.9.1
fixed
suse enterprise server 15 SP7
8.3.5-150400.3.9.1
fixed
python311-pytest-cov
suse enterprise desktop 15 SP6
6.2.1-150400.12.6.1
fixed
suse enterprise desktop 15 SP7
6.2.1-150400.12.6.1
fixed
suse enterprise sap 15 SP6
6.2.1-150400.12.6.1
fixed
suse enterprise sap 15 SP7
6.2.1-150400.12.6.1
fixed
suse enterprise server 15 SP4
6.2.1-150400.12.6.1
fixed
suse enterprise server 15 SP5
6.2.1-150400.12.6.1
fixed
suse enterprise server 15 SP6
6.2.1-150400.12.6.1
fixed
suse enterprise server 15 SP7
6.2.1-150400.12.6.1
fixed
python311-pytest-mock
suse enterprise desktop 15 SP6
3.14.0-150400.13.6.1
fixed
suse enterprise desktop 15 SP7
3.14.0-150400.13.6.1
fixed
suse enterprise sap 15 SP6
3.14.0-150400.13.6.1
fixed
suse enterprise sap 15 SP7
3.14.0-150400.13.6.1
fixed
suse enterprise server 15 SP4
3.14.0-150400.13.6.1
fixed
suse enterprise server 15 SP5
3.14.0-150400.13.6.1
fixed
suse enterprise server 15 SP6
3.14.0-150400.13.6.1
fixed
suse enterprise server 15 SP7
3.14.0-150400.13.6.1
fixed
system-user-pgadmin
suse enterprise desktop 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise desktop 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise sap 15 SP7
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP6
8.5-150600.3.6.1
fixed
suse enterprise server 15 SP7
8.5-150600.3.6.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grafana
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-azure-monitor
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-cloudwatch
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-elasticsearch
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-graphite
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-influxdb
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-loki
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-mssql
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-mysql
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-opentsdb
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-postgres
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-prometheus
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed
grafana-stackdriver
RHEL 8.2 AUS
0:6.3.6-6.el8_2
fixed