Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1576 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds. |
Github GHSA |
GHSA-x4jg-mjrx-434g | Improper Verification of Cryptographic Signature in node-forge |
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
|
|
| CPEs | cpe:/a:redhat:acm:2.4::el8 | |
| Vendors & Products |
Redhat acm
|
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat acm
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:46:10.614Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24772
No data.
Status : Modified
Published: 2022-03-18T14:15:10.353
Modified: 2026-06-17T04:32:29.150
Link: CVE-2022-24772
OpenCVE Enrichment
No data.
-
CWE-347
Improper Verification of Cryptographic Signature
EUVD
Github GHSA