Junglewise Threat Intelligence

Stark Bank ecdsa libraries signature forgery

Severity: info · Published 2021-11-08

Vendors: Maven, PyPI.

Executive brief

Stark Bank's ECDSA cryptographic libraries contain a flaw that allows attackers to forge digital signatures that will verify as valid against any public key. This breaks the authentication and authorization mechanism relied upon by the Stark Bank platform and any third parties using these libraries, potentially allowing attackers to impersonate users, authorize fraudulent transactions, and transfer funds without legitimate authorization.

Technical details

The vulnerability is a signature verification weakness (CWE-347) in Stark Bank's ECDSA implementations across multiple languages (Python, Java, .NET, Node.js). The root cause is insufficient range validation on signature components (r and s values), allowing attackers to craft forged signatures that pass verification checks for arbitrary messages and any public key. The attack requires no authentication or special network positioning—an attacker can generate valid-looking signatures offline. Exploitation allows complete bypass of signature-based authentication and authorization controls. Patches are available: Python 2.0.1+, Java 1.0.1+, .NET 1.3.2+, Node.js 1.1.3+.

Affected products

  • Stark Bank ecdsa (Python) 0.x, 1.x, 2.0.0
  • Stark Bank ecdsa (Java) 1.0.0
  • Stark Bank ecdsa (.NET) 1.3.1
  • Stark Bank ecdsa (Node.js) 1.1.2

Timeline

  • 2021-11-08: disclosed: Vulnerability published on GitHub Advisory Database and NCC Group technical advisory released
  • 2021-11-08: patched: Fixes released: Python 2.0.1, Java 1.0.1, .NET 1.3.2, Node.js 1.1.3

References

Related threats