kjur jsrsasign
cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:node.js:*:*
- <= 11.1.0
A vulnerability exists in jsrsasign version 11.1.0, where the encryption strength is inadequate. This issue arises because the HMAC and RSA key lengths used in the JSON Web Signature (JWS) implementation do not comply with recommended security standards. As a result, the vulnerability could potentially be exploited, leading to serious security risks.
The weak encryption can be exploited to compromise the security of cryptographic operations, such as signature validation or encryption/decryption processes, potentially allowing for unauthorized access or manipulation of data.
Users can upgrade to jsrsasign version 11.1.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.