Insecure Credential Comparison
Affecting safe-compare package, versions >=1.1.0 <1.1.2
safe-compare is a constant-time comparison algorithm to prevent timing attacks..
Affected versions of the package are vulnerable to Insecure Credential Comparison. It used the
bufferAlloc constructor incorrectly, which caused the password string to be "padded" with itself. This means that the passwords
"aaaaaaaaaaaaa" would be equal.
safe-compare to version 1.1.2 or higher.
Do your applications use this vulnerable package?
- Snyk Security Research Team
- Snyk ID
- 21 Feb, 2018
- 17 Apr, 2018