CVE-2024-49365
Last modified
CVE-2024-49365 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This affects only environments where require('buffer') is the NPM buffer package. Buffer.isBuffer check can be bypassed, resulting in strange objects being accepted as a message, and those messages could trick verify() into returning false-positive true values. This issue has been patched in version 1.1.7.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-49365?
How severe is CVE-2024-49365?
How do I fix CVE-2024-49365?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4936The Canto plugin for WordPress is vulnerable to Remote File …9.8
- CVE-2024-49360Sandboxie is a sandbox-based isolation software for 32-bit a…8.4
- CVE-2024-49361ACON is a widely-used library of tools for machine learning …8.1
- CVE-2024-49362Joplin is a free, open source note taking and to-do applicat…9.6
- CVE-2024-49363Misskey is an open source, federated social media platform. …7.4
- CVE-2024-49364tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior …8.1
- CVE-2024-49366Nginx UI is a web user interface for the Nginx web server. N…7.5
- CVE-2024-49367Nginx UI is a web user interface for the Nginx web server. P…7.5
- CVE-2024-49368Nginx UI is a web user interface for the Nginx web server. P…9.8
- CVE-2024-49369Icinga is a monitoring system which checks the availability …9.8
- CVE-2024-49370Pimcore is an open source data and experience management pla…4.9
- CVE-2024-49373No Fuss Computing Centurion ERP is open source enterprise re…4.3
Are you affected by CVE-2024-49365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
