Vulnerability Details CVE-2023-41037
OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. In affected versions OpenPGP Cleartext Signed Messages are cryptographically signed messages where the signed text is readable without special tools. These messages typically contain a "Hash: ..." header declaring the hash algorithm used to compute the signature digest. OpenPGP.js up to v5.9.0 ignored any data preceding the "Hash: ..." texts when verifying the signature. As a result, malicious parties could add arbitrary text to a third-party Cleartext Signed Message, to lead the victim to believe that the arbitrary text was signed. A user or application is vulnerable to said attack vector if it verifies the CleartextMessage by only checking the returned `verified` property, discarding the associated `data` information, and instead _visually trusting_ the contents of the original message. Since `verificationResult.data` would always contain the actual signed data, users and apps that check this information are not vulnerable. Similarly, given a CleartextMessage object, retrieving the data using `getText()` or the `text` field returns only the contents that are considered when verifying the signature. Finally, re-armoring a CleartextMessage object (using `armor()` will also result in a "sanitised" version, with the extraneous text being removed. This issue has been addressed in version 5.10.1 (current stable version) which will reject messages when calling `openpgp.readCleartextMessage()` and in version 4.10.11 (legacy version) which will will reject messages when calling `openpgp.cleartext.readArmored()`. Users are advised to upgrade. Users unable to upgrade should check the contents of `verificationResult.data` to see what data was actually signed, rather than visually trusting the contents of the armored message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.4%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2023-41037
-
cpe:2.3:a:openpgpjs:openpgpjs:*
-
cpe:2.3:a:openpgpjs:openpgpjs:0.1.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.10.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.10.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.10.2
-
cpe:2.3:a:openpgpjs:openpgpjs:0.10.3
-
cpe:2.3:a:openpgpjs:openpgpjs:0.11.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.11.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.2.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.2.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.3.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.3.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.3.2
-
cpe:2.3:a:openpgpjs:openpgpjs:0.4.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.4.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.5.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.5.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.6.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.6.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.6.2
-
cpe:2.3:a:openpgpjs:openpgpjs:0.6.3
-
cpe:2.3:a:openpgpjs:openpgpjs:0.6.5
-
cpe:2.3:a:openpgpjs:openpgpjs:0.7.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.7.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.7.2
-
cpe:2.3:a:openpgpjs:openpgpjs:0.8.0
-
cpe:2.3:a:openpgpjs:openpgpjs:0.8.1
-
cpe:2.3:a:openpgpjs:openpgpjs:0.8.2
-
cpe:2.3:a:openpgpjs:openpgpjs:0.9.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.0.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.0.1
-
cpe:2.3:a:openpgpjs:openpgpjs:1.1.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.2.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.3.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.4.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.4.1
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.1
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.2
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.3
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.4
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.5
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.6
-
cpe:2.3:a:openpgpjs:openpgpjs:1.5.7
-
cpe:2.3:a:openpgpjs:openpgpjs:1.6.0
-
cpe:2.3:a:openpgpjs:openpgpjs:1.6.1
-
cpe:2.3:a:openpgpjs:openpgpjs:1.6.2
-
cpe:2.3:a:openpgpjs:openpgpjs:2.0.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.0.1
-
cpe:2.3:a:openpgpjs:openpgpjs:2.1.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.2.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.2.1
-
cpe:2.3:a:openpgpjs:openpgpjs:2.2.2
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.1
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.2
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.3
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.4
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.5
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.6
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.7
-
cpe:2.3:a:openpgpjs:openpgpjs:2.3.8
-
cpe:2.3:a:openpgpjs:openpgpjs:2.4.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.1
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.10
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.11
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.12
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.13
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.14
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.2
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.3
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.4
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.5
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.6
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.7
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.8
-
cpe:2.3:a:openpgpjs:openpgpjs:2.5.9
-
cpe:2.3:a:openpgpjs:openpgpjs:2.6.0
-
cpe:2.3:a:openpgpjs:openpgpjs:2.6.1
-
cpe:2.3:a:openpgpjs:openpgpjs:2.6.2
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.0
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.1
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.10
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.11
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.12
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.13
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.2
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.3
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.4
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.6
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.7
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.8
-
cpe:2.3:a:openpgpjs:openpgpjs:3.0.9
-
cpe:2.3:a:openpgpjs:openpgpjs:3.1.0
-
cpe:2.3:a:openpgpjs:openpgpjs:3.1.1
-
cpe:2.3:a:openpgpjs:openpgpjs:3.1.2
-
cpe:2.3:a:openpgpjs:openpgpjs:3.1.3
-
cpe:2.3:a:openpgpjs:openpgpjs:4.0.0
-
cpe:2.3:a:openpgpjs:openpgpjs:4.0.1
-
cpe:2.3:a:openpgpjs:openpgpjs:4.0.2
-
cpe:2.3:a:openpgpjs:openpgpjs:4.1.0
-
cpe:2.3:a:openpgpjs:openpgpjs:4.1.1
-
cpe:2.3:a:openpgpjs:openpgpjs:4.1.2
-
cpe:2.3:a:openpgpjs:openpgpjs:4.2.0
-
cpe:2.3:a:openpgpjs:openpgpjs:4.2.1
-
cpe:2.3:a:openpgpjs:openpgpjs:4.2.2
-
cpe:2.3:a:openpgpjs:openpgpjs:4.3.0
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.1
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.10
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.2
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.3
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.4
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.5
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.6
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.7
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.8
-
cpe:2.3:a:openpgpjs:openpgpjs:4.4.9
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.0
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.1
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.2
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.3
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.4
-
cpe:2.3:a:openpgpjs:openpgpjs:4.5.5
-
cpe:2.3:a:openpgpjs:openpgpjs:4.6.0