PT-2024-26945 · Freefrom · Freefrom

Hayato Kimura

+3

·

Published

2024-06-17

·

Updated

2024-08-02

·

CVE-2024-36277

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreeFrom - the nostr client versions prior to 1.3.5
Description The issue is related to improper verification of cryptographic signatures. This means the affected app cannot detect event data with invalid signatures, potentially allowing unauthorized or tampered data to be accepted as valid.
Recommendations For versions prior to 1.3.5, update to version 1.3.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the app until the update is applied.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2024-36277

Affected Products

Freefrom