GHSA-c35v-qwqg-87jc
LOWVersions of express-basic-auth prior to 1.1.7 are vulnerable to Timing Attacks. The package uses native string comparison instead of a constant time string comparison, which may lead to Timing Attacks. Timing Attacks can be used to increase the efficiency of brute-force attacks by removing the exponential increase in entropy gained from longer secrets.
- Affected
- < 1.1.7
- Fixed in
- 1.1.7
- Weakness
- CWE-208
- Published
- 2019-06-06
- Source
- github