Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Improper Verification of Cryptographic Signature (CVE-2024-48948) #323

Open
avembankottu opened this issue Oct 17, 2024 · 9 comments
Open

Comments

@avembankottu
Copy link

https://security.snyk.io/vuln/SNYK-JS-ELLIPTIC-8187303

@bora-yuksel-1
Copy link

+1 to this, seems like a PR is already open for this issue: #322

@un4ckn0wl3z
Copy link

+1

@avembankottu
Copy link
Author

any idea when will it get merged ?

@LordOfCinder2000
Copy link

+1

@paulmillr
Copy link

  1. This is not CVE: just a bug.
  2. Maintainer is currently focused on other important things, so it's unclear when it would be fixed.
  3. Switch to newer package noble-curves instead.

@jcheung-xmatters
Copy link

+1
Unfortunately it's not as simple as "switch to another package", as this library is a dependency 4 levels down in my project.

@chadlwilson
Copy link

Fixed in 6.6.0 via #326 - you can close this issue now.

@avembankottu
Copy link
Author

Snyk complaining that the vuln still exist in 6.6.0 via #326 @chadlwilson

@chadlwilson
Copy link

Then you should contact Snyk to ask them to re-assess and update the fixed version. An OSS project with volunteer contributors does not control proprietary security tool databases - there's no point complaining about that here.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants