Bypassing verification in the xml-crypto library, which has a million downloads per week.

A vulnerability (CVE-2024-32962) has been discovered in the xml-crypto JavaScript library, which is used as a dependency in 402 projects and downloaded from the NPM registry approximately one million times each week. It has been assigned the highest severity rating (10 out of 10). The library provides functions for encrypting and verifying XML documents through digital signatures. The vulnerability allows an attacker to sign a fake document that, under default configuration, will be successfully verified by the library, even though it is signed with a key that is different from the one specified for signature verification. This issue arises starting from version xml-crypto 4.0.0 and has been discreetly fixed in the January release of 6.0.0.

The vulnerability is caused by the library not authenticating the signature creator in its default configuration; it only checks the validity of the signature itself. Specifically, the library trusts any certificate placed in the signed document within the XML KeyInfo element, even if the settings specify the use of a particular certificate for verifying digital signatures. Therefore, for successful verification of a modified document, an attacker only needs to replace the original digital signature with a signature created using their private key and place the corresponding certificate (public key) in the KeyInfo element.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster