Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpmc-qchh-r9q8

Опубликовано: 08 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.5

Описание

Altcha Proof-of-Work obfuscation mode cryptanalytic break

A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via mathematical deduction.

Пакеты

Наименование

altcha

npm
Затронутые версииВерсия исправления

>= 0.8.0, <= 2.2.4

Отсутствует

EPSS

Процентиль: 3%
0.00017
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 9.1
nvd
2 месяца назад

A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via mathematical deduction. NOTE: this is disputed by the Supplier because the product's objective is "to discourage automated scraping / bots, not guarantee resistance to determined attackers." The documentation states “the goal is not to provide a secure cryptographic algorithm but to use a proof-of-work mechanism that allows any capable device to decrypt the hidden data.”

EPSS

Процентиль: 3%
0.00017
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-327