Описание
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.1 (исключая)
cpe:2.3:a:secure-compare_project:secure-compare:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 44%
0.00217
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-697
CWE-134
Связанные уязвимости
EPSS
Процентиль: 44%
0.00217
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-697
CWE-134