Uploaded image for project: 'JOC - JS7 Operations Center'
  1. JOC - JS7 Operations Center
  2. JOC-2213

Update elliptic version 6.6.1 due to 3rd-party vulnerability CVE-2025-14505

    XMLWordPrintable

Details

    • CVE-2025-14505

    Description

      Impact
      Indirect dependency via jwk-to-pem. Used only for JWT verification. Vulnerable code path (ECDSA signing) is not used. No upstream fix available.

      Maintainer Note
      The issue is dismissed as no update version of the elliptic package is available.

      Attachments

        Activity

          People

            ZTNEERAJ303 Neeraj Patidar
            ap Andreas Püschel
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: