org.webjars.npm:http-signature@0.10.1 vulnerabilities
-
latest version
1.3.6
-
latest non vulnerable version
-
first published
9 years ago
-
latest version published
2 years ago
-
licenses detected
- [0.10.1,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.webjars.npm:http-signature package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of the package are vulnerable to Timing Attacks due to time-variable comparison of signatures. The library implemented a character to character comparison, similar to the built-in string comparison mechanism, You can read more about timing attacks in Node.js on the Snyk blog. How to fix Timing Attack? Upgrade |
[,1.0.0)
|