simple-otp@0.1.0 vulnerabilities

A simple OTP Generation and Verification Library which works without a Database or Cache

  • latest version

    0.1.1

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    2 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the simple-otp package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Timing Attack

    simple-otp is an A simple OTP Generation and Verification Library which works without a Database or Cache

    Affected versions of this package are vulnerable to Timing Attack due to using == operator when comparing hashes.

    How to fix Timing Attack?

    Upgrade simple-otp to version 0.1.1 or higher.

    [,0.1.1)
    • M
    Cryptographic Issues

    simple-otp is an A simple OTP Generation and Verification Library which works without a Database or Cache

    Affected versions of this package are vulnerable to Cryptographic Issues due to using cryptographically insecure random numbers.

    How to fix Cryptographic Issues?

    Upgrade simple-otp to version 0.1.1 or higher.

    [,0.1.1)