Описание
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-cookie-signature | fixed | 1.1.0-1 | package |
Примечания
https://nodesecurity.io/advisories/134
https://github.com/tj/node-cookie-signature/commit/39791081692e9e14aa62855369e1c7f80fbfd50e
nodejs not covered by security support
EPSS
Процентиль: 57%
0.00896
Низкий
Связанные уязвимости
CVSS3: 4.4
ubuntu
больше 6 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVSS3: 5.4
redhat
около 12 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVSS3: 4.4
nvd
больше 6 лет назад
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
EPSS
Процентиль: 57%
0.00896
Низкий