1.4.2
1 years ago
11 days ago
Known vulnerabilities in the openssl-encrypt package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Use of GET Request Method With Sensitive Query Strings via the How to fix Use of GET Request Method With Sensitive Query Strings? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Incorrect Authorization via the CORS configuration. An attacker can gain unauthorized access to sensitive API endpoints by making authenticated cross-origin requests from a malicious website. How to fix Incorrect Authorization? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Missing Authorization in the How to fix Missing Authorization? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the How to fix Insertion of Sensitive Information Into Sent Data? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the How to fix Improper Verification of Cryptographic Signature? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Uncontrolled Search Path Element through the dynamic loading in How to fix Uncontrolled Search Path Element? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the use of an in-memory How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Credential Exposure via the How to fix Credential Exposure? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Improper Check for Unusual or Exceptional Conditions in the schema validation when the How to fix Improper Check for Unusual or Exceptional Conditions? Upgrade | [,1.4.0) |
openssl-encrypt is an A package for secure file encryption and decryption based on modern ciphers using heavy-compute-load chaining of hashing and KDF to generate strong encryption password based on users provided password to ensure secure encryption of files Affected versions of this package are vulnerable to Insufficient Entropy in the How to fix Insufficient Entropy? Upgrade | [,1.4.0) |