cookie-signature@0.0.1 vulnerabilities
Sign and unsign cookies
-
latest version
1.2.1
-
latest non vulnerable version
-
first published
11 years ago
-
latest version published
9 months ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the cookie-signature package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
'cookie-signature' is a library for signing cookies. Versions before You can read more about timing attacks in Node.js on the Snyk blog: https://snyk.io/blog/node-js-timing-attack-ccc-ctf/ How to fix Non-Constant Time String Comparison? Upgrade to |
<1.0.4
|