CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2020-14968

CVSS 9.8v3.1pub. 2020-06-22upd. 2026-06-22

An issue was discovered in the jsrsasign package before 8.0.17 for Node.js. Its RSASSA-PSS (RSA-PSS) implementation does not detect signature manipulation/modification by prepending '\0' bytes to a signature (it accepts these modified signatures as valid). An attacker can abuse this behavior in an application by creating multiple valid signatures where only one signature should exist. Also, an attacker might prepend these bytes with the goal of triggering memory corruption issues.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Kjur Jsrsasign

    APP
    Kjur
    < 8.0.17
  • Netapp Max Data

    APP
    Netapp
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-4599CRITICAL9.3PL ✓same product

Odtworzenie klucza prywatnego DSA przez błąd porównań w jsrsasign

CVE-2021-30246CRITICAL9.1PL ✓same product

Błędna weryfikacja podpisów RSA PKCS#1 v1.5 w jsrsasign

CVE-2020-15801CRITICAL9.8PL ✓same product

Python 3.8.4 – ignorowanie ograniczeń sys.path z pliku python38._pth

CVE-2020-14967CRITICAL9.8PL ✓same product

Błąd weryfikacji szyfrogramu RSA PKCS1 v1.5 w bibliotece jsrsasign

CVE-2026-4598HIGH7.7same product

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function ...