In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere's no official fix for the vulnerability. In the meanwhile, consider switching to a 'different npm module'.
'node-krb5' is a node.js native add-on for simple krb5 user authentication.
Current implementation does not verify the Kerberos Key Distribution Center (KDC): it accepts a username/password from the user, then asks a KDC whether that password is correct for the corresponding Kerberos principal - without assurance that the response came from a real KDC.