eth-keyfile@0.5.1 vulnerabilities

eth-keyfile: A library for handling the encrypted keyfiles used to store ethereum private keys

  • latest version

    0.8.1

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    8 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the eth-keyfile package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Timing Attack

    eth-keyfile is an A library for handling the encrypted keyfiles used to store ethereum private keys.

    Affected versions of this package are vulnerable to Timing Attack. When checking mac while decoding a keyfile, a non-constant time compare function is used.

    How to fix Timing Attack?

    Upgrade eth-keyfile to version 0.6.0 or higher.

    [,0.6.0)