11.1.1
12 years ago
1 months ago
Known vulnerabilities in the jsrsasign package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Division by zero due to the How to fix Division by zero? Upgrade | <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in How to fix Incorrect Conversion between Numeric Types? Upgrade | <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Missing Cryptographic Step via the How to fix Missing Cryptographic Step? Upgrade | <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in How to fix Improper Verification of Cryptographic Signature? Upgrade | <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Incomplete Comparison with Missing Factors via the How to fix Incomplete Comparison with Missing Factors? Upgrade | >=7.0.0 <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Infinite loop via the How to fix Infinite loop? Upgrade | <11.1.1 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Observable Discrepancy via the RSA PKCS#1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. How to fix Observable Discrepancy? Upgrade | <11.0.0 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature when How to fix Improper Verification of Cryptographic Signature? Upgrade | <10.5.25 |
jsrsasign is a free pure JavaScript cryptographic library. Affected versions of this package are vulnerable to Cryptographic Weakness. Invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized to be valid. How to fix Cryptographic Weakness? Upgrade | <10.1.13 |