Skip to content
This repository was archived by the owner on Oct 1, 2025. It is now read-only.

fix: signature used for direct signing is unchecked#105

Closed
yehjxraymond wants to merge 1 commit intomasterfrom
fix/uncheckedSignature
Closed

fix: signature used for direct signing is unchecked#105
yehjxraymond wants to merge 1 commit intomasterfrom
fix/uncheckedSignature

Conversation

@yehjxraymond
Copy link
Contributor

Severity: Info

Signature used for direct signing is unchecked

Independently, this issue does not make any documents vulnerable. Once it is chained with the upcoming PR #93, an adversary can issue document from a legitimate organisation using their domain when it adds in a valid signature from an unknown address and reusing the documentStore and DNS-TXT from the legitimate organisation in the document.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant