Описание
bsock uses weak hashing algorithms
An issue was discovered in the bsock component of bcoin-org bcoin that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-50475
- https://github.com/bcoin-org/bcoin/issues/1174
- https://github.com/bcoin-org/bcoin/blob/master/node_modules/bsock/package.json
- https://github.com/bcoin-org/bsock/blob/master/package.json
- https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-50475.md
Пакеты
Наименование
bsock
npm
Затронутые версииВерсия исправления
<= 0.1.11
Отсутствует
Связанные уязвимости
CVSS3: 9.1
nvd
около 2 лет назад
An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.