Description
Affected versions of cookie-signature are vulnerable to timing attacks as a result of using a fail-early comparison instead of a constant-time comparison.
Recommendation
Update the cookie-signature package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.4
- Patched version(s): 1.0.4
References
Could your website be exposed too?
SmartScanner can check your website for cookie-signature Timing Attack and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime - CVE-2021-29445
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtime - CVE-2021-29446
- browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack - CVE-2023-46234
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtime - CVE-2021-29444
You might also like:
See something that needs correcting? Let us knowUpdated January 11, 2023


