SCA: security update for secp256k1 (GHSA-584q-6j8j-r5pm)

high Tenable Self-Hosted Container Security Plugin ID 410679

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In
`elliptic`-based version, `loadUncompressedPublicKey` has a check that the public key is on the curve.
Prior to versions 5.0.1, 4.0.4, and 3.8.1, however, `loadCompressedPublicKey` is missing that check. That
allows the attacker to use public keys on low-cardinality curves to extract enough information to fully
restore the private key from as little as 11 ECDH sessions, and very cheaply on compute power. Other
operations on public keys are also affected, including e.g. `publicKeyVerify()` incorrectly returning
`true` on those invalid keys, and e.g. `publicKeyTweakMul()` also returning predictable outcomes allowing
to restore the tweak. Versions 5.0.1, 4.0.4, and 3.8.1 contain a fix for the issue. (CVE-2024-48930)

See Also

https://github.com/advisories/GHSA-584q-6j8j-r5pm

Plugin Details

Severity: High

ID: 410679

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-48930

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/21/2024

Vulnerability Publication Date: 10/21/2024

Reference Information

CVE: CVE-2024-48930