ecdh@0.1.1 vulnerabilities

Native node.js module for ECDH and ECDSA

Direct Vulnerabilities

Known vulnerabilities in the ecdh package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

ecdh is a native Node.js module for ECDH and ECDSA

Affected versions of this package are vulnerable to Information Exposure in the deriveSharedSecret() function in index.js, which allows an attacker to send an invalid point as the public key (a point not on the curve), and retrieve the derived shared secret.

How to fix Information Exposure?

Upgrade ecdh to version 0.2.0 or higher.

<0.2.0