Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1274 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid structures but a valid digest. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds. |
Github GHSA |
GHSA-2r2c-g63r-vccr | Improper Verification of Cryptographic Signature in `node-forge` |
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
|
|
| CPEs | cpe:/a:redhat:acm:2.4::el8 | |
| Vendors & Products |
Redhat acm
|
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat acm
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:46:17.431Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24773
No data.
Status : Modified
Published: 2022-03-18T14:15:10.427
Modified: 2026-06-17T04:32:29.367
Link: CVE-2022-24773
OpenCVE Enrichment
No data.
-
CWE-347
Improper Verification of Cryptographic Signature
EUVD
Github GHSA