2.3.0
1 years ago
1 months ago
Known vulnerabilities in the org.webjars.npm:altcha package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.webjars.npm:altcha is a Privacy-first CAPTCHA widget, compliant with global regulations (GDPR/HIPAA/CCPA/LGDP/DPDPA/PIPL) and WCAG accessible. No tracking, self-verifying. Affected versions of this package are vulnerable to Inadequate Encryption Strength in the Proof of Work obfuscation scheme. An attacker can recover sensitive nonce values by performing mathematical deduction in constant time. Note: Vendor mitigated this issue by moving the affected obfuscation plugin out of the main package.
However, the problematic cryptographic limitation is present in For more details, see vendor's Migration Guide to v2.3.0 How to fix Inadequate Encryption Strength? Upgrade | [,2.3.0) |