jsrsasign is vulnerable to Improper Verification of Cryptographic Signature
80
High Risk
Affected versions of this package are vulnerable to signature forgery due to incorrect boundary validation in the DSA verification logic. The verifyWithMessageHash function does not properly enforce parameter constraints defined in FIPS 186-4, allowing specially crafted signature values to bypass verification checks. An attacker able to supply such malformed signatures can forge valid-looking signatures without possession of the private key, potentially leading to authentication bypass or integrity compromise.
You are affected if you are using a version that falls within the vulnerable range.
jsrsasign is vulnerable to Improper Verification of Cryptographic Signature in versions 7.1.0 - 11.1.1.
Upgrade the jsrsasign library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant