Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1403 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses unchecked portion of the PKCS#1 encoded message to forge a signature when a low public exponent is being used. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds. |
Github GHSA |
GHSA-cfm4-qjh2-4765 | Improper Verification of Cryptographic Signature in node-forge |
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
|
|
| CPEs | cpe:/a:redhat:acm:2.4::el8 | |
| Vendors & Products |
Redhat acm
|
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat acm
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:46:25.686Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24771
Updated: 2024-08-03T04:20:50.502Z
Status : Modified
Published: 2022-03-18T14:15:10.280
Modified: 2024-11-21T06:51:03.860
Link: CVE-2022-24771
OpenCVE Enrichment
No data.
EUVD
Github GHSA