fernet@0.0.2 vulnerabilities
Javascript implementation of Fernet symmetric encryption https://github.com/kr/fernet-spec
-
latest version
0.3.2
-
latest non vulnerable version
-
first published
11 years ago
-
latest version published
9 months ago
-
licenses detected
- >=0.0.1 <0.3.0
Direct Vulnerabilities
Known vulnerabilities in the fernet package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
The library implemented a character to character comparison, similar to the built-in string comparison mechanism, You can read more about timing attacks in Node.js on the Snyk blog. How to fix Timing Attack? Upgrade |
>=0.0.1 <0.1.0
|