GHSA-c35v-qwqg-87jc

    Dashboard / Vulnerabilities / GHSA-c35v-qwqg-87jc

    GHSA-c35v-qwqg-87jc

    Published: 6 Jun 2019Last Modified: 3 Aug 2022

    Summary: express-basic-auth Timing Attack due to native string comparison instead of constant time string comparison

    Details: Versions of `express-basic-auth` prior to 1.1.7 are vulnerable to Timing Attacks. The package uses native string comparison instead of a constant time string comparison, which may lead to Timing Attacks. Timing Attacks can be used to increase the efficiency of brute-force attacks by removing the exponential increase in entropy gained from longer secrets. ## Recommendation Upgrade to version 1.1.7 or later.

    Affected packages

    Package

    Name: express-basic-auth

    Purl: pkg:npm/express-basic-auth

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.1.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-c35v-qwqg-87jc | CVE-DB