manifest@4.0.1-beta.2 vulnerabilities

The 1-file micro-backend

  • latest version

    4.11.0

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    9 days ago

  • licenses detected

    • >=0.0.1 <2.0.0; >=4.0.0-alpha.0
  • Direct Vulnerabilities

    Known vulnerabilities in the manifest package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Use of a One-Way Hash without a Salt

    manifest is a The 1-file micro-backend

    Affected versions of this package are vulnerable to Use of a One-Way Hash without a Salt. In the AuthService class in auth.service.ts, passwords are hashed using SHA3 without a salt. An attacker in possession of the user database can discover that passwords for multiple users are identical due to their identical hashes.

    How to fix Use of a One-Way Hash without a Salt?

    Upgrade manifest to version 4.9.2 or higher.

    <4.9.2