Skip to content
This repository has been archived by the owner on Nov 24, 2021. It is now read-only.

Dependency on a library with a Medium severity CVE

Low
intelliot published GHSA-w6x3-9ph2-7x54 Feb 23, 2021

Package

npm ripple-keypairs (npm)

Affected versions

< 1.0.3

Patched versions

1.0.3

Description

Impact

No expected impact on ripple-keypairs, because the attack only applies to encrypting messages for Diffie-Helman key exchange, which we do not do

Patches

1.0.3 - yarn.lock uses the patched version of elliptic (v6.5.4)

Workarounds

Not needed

References

https://github.com/ripple/ripple-keypairs/blob/master/HISTORY.md#103-2021-02-22
https://nvd.nist.gov/vuln/detail/CVE-2020-28498

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2020-28498

Weaknesses