CVE-2024-32962
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of ...
Affects 0 products across 4 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2024-32962 affects the xml-crypto library for Node.js, where the default configuration does not verify the signer's authorization, allowing malicious actors to re-sign XML documents without proper validation.
BSID: BS-2024-GLOBAL-049876-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-32962?
What is the CVSS score for CVE-2024-32962?
Is CVE-2024-32962 actively exploited?
How do I remediate CVE-2024-32962?
What systems are affected by CVE-2024-32962?
| CVE ID | CVE-2024-32962 |
|---|---|
| BSID | BS-2024-GLOBAL-049876-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| Published | 2024-05-02 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<KeyInfo />`. `xml-crypto` prefers to use any certificate provided via digitally signed XML document's `<KeyInfo />` even if library was configured to use specific certificate (`publicCert`) for signature verification purposes. An attacker can spoof signature verification by modifying XML document and replacing existing signature with signature generated with malicious private key (created by attacker) and by attaching that private key's certificate to `<KeyInfo />` element. This vulnerability is combination of changes introduced to `4.0.0` on pull request 301 / commit `c2b83f98` and has been addressed in version 6.0.0 with pull request 445 / commit `21201723d`. Users are advised to upgrade. Users unable to upgrade may either check the certificate extracted via `getCertFromKeyInfo` against trusted certificates before accepting the results of the validation or set `xml-crypto's getCertFromKeyInfo` to `() => undefined` forcing `xml-crypto` to use an explicitly configured `publicCert` or `privateKey` for signature verification.
Source: NIST NVD / MITRE CVE Database
A malicious actor can exploit this vulnerability by re-signing XML documents with unauthorized keys, potentially leading to the acceptance of tampered data as legitimate.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Crypto | — | — |
| Digital | — | — |
| Element | — | — |
| Place | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 39490b3802860dfac61771be7db27ad80cfa4c0b14b825aa5a8970aa2f527170c806a80d920880216fe5b9fd3319478f2157a5d80c9c05a0f0d6187db0264816 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →