Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c35v-qwqg-87jc

Опубликовано: 06 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

express-basic-auth Timing Attack due to native string comparison instead of constant time string comparison

Versions of express-basic-auth prior to 1.1.7 are vulnerable to Timing Attacks. The package uses native string comparison instead of a constant time string comparison, which may lead to Timing Attacks. Timing Attacks can be used to increase the efficiency of brute-force attacks by removing the exponential increase in entropy gained from longer secrets.

Recommendation

Upgrade to version 1.1.7 or later.

Пакеты

Наименование

express-basic-auth

npm
Затронутые версииВерсия исправления

< 1.1.7

1.1.7

3.1 Low

CVSS3

Дефекты

CWE-208

3.1 Low

CVSS3

Дефекты

CWE-208