-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/free5gc/udm | go | < 1.2.0 | 1.2.0 |
The vulnerability stems from the lack of elliptic curve point validation in profileB before Go 1.19's security improvements. The patch adds checkOnCurve validation specifically in profileB, and the CWE-347 (Improper Verification of Cryptographic Signature) directly maps to this missing validation. The test case added in the commit demonstrates rejection of invalid curve points, confirming the vulnerability existed in profileB's ECC operations prior to validation being implemented.
Ongoing coverage of React2Shell