Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improper Verification of Cryptographic Signature (CVE-2024-48948) #323

Open
avembankottu opened this issue Oct 17, 2024 · 9 comments
Open

Comments

@avembankottu
Copy link

https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303

@bora-yuksel-1
Copy link

+1 to this, seems like a PR is already open for this issue: #322

@un4ckn0wl3z
Copy link

+1

@avembankottu
Copy link
Author

any idea when will it get merged ?

@LordOfCinder2000
Copy link

+1

@paulmillr
Copy link

  1. This is not CVE: just a bug.
  2. Maintainer is currently focused on other important things, so it's unclear when it would be fixed.
  3. Switch to newer package noble-curves instead.

@jcheung-xmatters
Copy link

+1
Unfortunately it's not as simple as "switch to another package", as this library is a dependency 4 levels down in my project.

@chadlwilson
Copy link

Fixed in 6.6.0 via #326 - you can close this issue now.

@avembankottu
Copy link
Author

Snyk complaining that the vuln still exist in 6.6.0 via #326 @chadlwilson

@chadlwilson
Copy link

Then you should contact Snyk to ask them to re-assess and update the fixed version. An OSS project with volunteer contributors does not control proprietary security tool databases - there's no point complaining about that here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants