Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| openpgp(npm) | 0 | 4.2.0 | N/A |
CVSS Metrics