Junglewise Threat Intelligence

CVE-2020-14967: jsrsasign RSA PKCS#1 decryption bypass with prepended zeros

CVE-2020-14967 · Severity: low · CVSS 3.1 · Published 2020-06-26

Technologies: Jsrsasign. Vendors: npm.

Executive brief

jsrsasign is a JavaScript library for cryptographic operations, including RSA encryption and decryption. The library fails to properly validate RSA-encrypted messages that contain prepended zeros, allowing an attacker to bypass decryption protections and potentially forge encrypted content. Applications using RSA PKCS#1 v1.5 or RSA-OAEP decryption are affected.

Technical details

The vulnerability exists in jsrsasign's RSA PKCS#1 v1.5 and RSA-OAEP decryption implementations, where encrypted messages are represented as BigInteger. Crafted messages with prepended zeros can be decrypted despite not being valid according to the RSA standard. The root cause is insufficient validation of the message format before decryption. No authentication or network access is required; an attacker must provide a malicious encrypted message to the application. An attacker can forge the contents of encrypted messages. Memory corruption risk is mitigated by jsrsasign's use of the BigInteger class. The patch is available in version 8.0.18.

Affected products

  • jsrsasign jsrsasign < 8.0.18

Timeline

  • 2020-06-22: disclosed
  • 2020-06-23: advisory
  • 2020-06-26: patched

References

Related threats