Description
An issue was discovered in the bsock component of bcoin-org bcoin that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.1.11
References
Related Issues
- EverShop at risk to unauthorized access via weak HMAC secret - CVE-2023-46943
- Hidden fields can be leaked on readable collections in Payload - CVE-2023-30843
- Axios Cross-Site Request Forgery Vulnerability - CVE-2023-45857
- Prototype Pollution in NASA Open MCT - CVE-2023-45282
You might also like:
- Tags:
- npm
- bsock
Anything's wrong? Let us know Last updated on January 02, 2024


