Описание
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-cookie-signature | fixed | 1.1.0-1 | package |
Примечания
https://nodesecurity.io/advisories/134
https://github.com/tj/node-cookie-signature/commit/39791081692e9e14aa62855369e1c7f80fbfd50e
nodejs not covered by security support
Связанные уязвимости
CVSS3: 4.4
ubuntu
около 6 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVSS3: 5.4
redhat
больше 11 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVSS3: 4.4
nvd
около 6 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.