safe-compare@1.1.1 vulnerabilities
Constant-time comparison algorithm to prevent timing attacks.
-
latest version
1.1.4
-
latest non vulnerable version
-
first published
9 years ago
-
latest version published
6 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the safe-compare package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
safe-compare is a Constant-time comparison algorithm to prevent Node.js timing attacks. Affected versions of this package are vulnerable to Timing Attack via the How to fix Timing Attack? Upgrade |
>=1.0.4 <1.1.4
|
Affected versions of the package are vulnerable to Insecure Credential Comparison. It used the How to fix Insecure Credential Comparison? Upgrade |
>=1.1.0 <1.1.2
|