Vulnerability Details CVE-2024-42461
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.8%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-42461
-
cpe:2.3:a:elliptic_project:elliptic:6.5.6