CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-14967

CVSS 9.8v3.1pub. 2020-06-22upd. 2026-06-22

An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modified ciphertexts without error). An attacker might prepend these bytes with the goal of triggering memory corruption issues.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Kjur Jsrsasign

    APP
    Kjur
    < 8.0.18
  • Netapp Max Data

    APP
    Netapp
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-4599CRITICAL9.3PL ✓same product

Odtworzenie klucza prywatnego DSA przez błąd porównań w jsrsasign

CVE-2021-30246CRITICAL9.1PL ✓same product

Błędna weryfikacja podpisów RSA PKCS#1 v1.5 w jsrsasign

CVE-2020-15801CRITICAL9.8PL ✓same product

Python 3.8.4 – ignorowanie ograniczeń sys.path z pliku python38._pth

CVE-2020-14968CRITICAL9.8PL ✓same product

Błąd weryfikacji podpisu RSA-PSS w bibliotece jsrsasign (Node.js)

CVE-2026-4598HIGH7.7same product

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function ...