CVE-2024-48948

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Oct 15, 2024
Updated: Dec 20, 2024
CWE ID 347

Summary

CVE-2024-48948 is a vulnerability affecting the Elliptic package version 6.5.7 used in Node.js for ECDSA signature verification. The issue arises when the hash contains leading zero bytes and the order of the elliptic curve's base point is smaller than the hash. This _truncateToN anomaly results in valid signatures being incorrectly rejected, potentially leading to legitimate transactions or communications being flagged as invalid. This vulnerability poses a risk for applications that rely on the Elliptic package for secure signature verification. Users are advised to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share