Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-434g-2637-qmqr | Elliptic's verify function omits uniqueness validation |
Tue, 25 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Dec 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 27 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Devspaces
|
|
| CPEs | cpe:/a:redhat:openshift_devspaces:3::el8 | |
| Vendors & Products |
Redhat openshift Devspaces
|
Fri, 22 Nov 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.8::el8 cpe:/a:redhat:multicluster_engine:2.3::el8 |
Thu, 07 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.12::el9 |
Wed, 06 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.10::el9 cpe:/a:redhat:multicluster_engine:2.5::el8 |
Tue, 29 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat multicluster Engine
|
|
| CPEs | cpe:/a:redhat:acm:2.9::el8 cpe:/a:redhat:multicluster_engine:2.4::el8 cpe:/a:redhat:rhel_aus:8.2 |
|
| Vendors & Products |
Redhat multicluster Engine
|
Wed, 23 Oct 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_tus:8.4 |
|
| Vendors & Products |
Redhat rhel Aus
Redhat rhel E4s Redhat rhel Tus |
Tue, 15 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Indutny
Indutny elliptic |
|
| CPEs | cpe:2.3:a:indutny:elliptic:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Indutny
Indutny elliptic |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Oct 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat acm |
|
| CPEs | cpe:/a:redhat:acm:2.11::el9 | |
| Vendors & Products |
Redhat
Redhat acm |
Fri, 11 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-347 |
Thu, 10 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | elliptic: Missing Validation in Elliptic's EDDSA Signature Verification | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 10 Oct 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-25T15:42:12.721Z
Reserved: 2024-10-10T00:00:00.000Z
Link: CVE-2024-48949
Updated: 2024-12-27T16:03:06.432Z
Status : Modified
Published: 2024-10-10T01:15:11.127
Modified: 2025-11-25T16:16:05.910
Link: CVE-2024-48949
OpenCVE Enrichment
No data.
Github GHSA