The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2024:8351 https://access.redhat.com/errata/RHSA-2024:8351
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:8507 https://access.redhat.com/errata/RHSA-2024:8507
CVE-2024-48949 has been solved in https://access.redhat.com/errata/RHSA-2024:6738 for Multicluster Engine for Kubernetes 2.5.7
CVE-2024-48949 has been solved in https://access.redhat.com/errata/RHSA-2024:6779 for Red Hat Advanced Cluster Management at 2.10.6
This issue has been addressed in the following products: Red Hat OpenShift Dev Spaces 3 Containers Via RHSA-2024:10236 https://access.redhat.com/errata/RHSA-2024:10236