Описание
Bit flip attack vulnerability in cookie-encrypter
due to a weakness in the encryption method used in cookie-encrypter an attack can use the world visible IV to edit encrypted cookies without decrypting the cookie itself. This is known as an AES CBC bit flipping attack.
Пакеты
Наименование
cookie-encrypter
npm
Затронутые версииВерсия исправления
<= 1.0.1
Отсутствует
Связанные уязвимости
CVSS3: 9.1
nvd
около 1 года назад
An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.