{"id":"GHSA-27fj-mc8w-j9wg","summary":"RSA signature validation vulnerability on maleable encoded message in jsrsasign","details":"### Impact\nVulnerable jsrsasign will accept RSA signature with improper PKCS#1.5 padding.\nDecoded RSA signature value consists following form:\n`01(ff...(8 or more ffs)...ff)00[ASN.1 OF DigestInfo]`\nIts byte length must be the same as RSA key length, however such checking was not sufficient.\n\nTo make crafted message for practical attack is very hard.\n\n### Patches\nUsers validating RSA signature should upgrade to 10.2.0 or later.\n\n### Workarounds\nThere is no workaround. Not to use RSA signature validation in jsrsasign.\n\n### ACKNOWLEDGEMENT\nThanks to Daniel Yahyazadeh @yahyazadeh for reporting and analyzing this vulnerability.","aliases":["CVE-2021-30246"],"modified":"2023-11-08T04:05:45.910717Z","published":"2021-04-16T19:52:35Z","database_specific":{"cwe_ids":["CWE-347"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-04-13T17:30:34Z","nvd_published_at":"2021-04-07T21:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/kjur/jsrsasign/security/advisories/GHSA-27fj-mc8w-j9wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-30246"},{"type":"WEB","url":"https://github.com/kjur/jsrsasign/issues/478"},{"type":"WEB","url":"https://github.com/kjur/jsrsasign/releases/tag/10.1.13"},{"type":"WEB","url":"https://kjur.github.io/jsrsasign"}],"affected":[{"package":{"name":"jsrsasign","ecosystem":"npm","purl":"pkg:npm/jsrsasign"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-27fj-mc8w-j9wg/GHSA-27fj-mc8w-j9wg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}