Description
Affected versions of cookie-signature are vulnerable to timing attacks as a result of using a fail-early comparison instead of a constant-time comparison.
Recommendation
Update the cookie-signature package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.4
- Patched version(s): 1.0.4
References
- GHSA-92vm-wfm5-mxvv
- bugs.debian.org
- bugzilla.redhat.com
- security-tracker.debian.org
- travis-ci.com
- www.mail-archive.com
- www.npmjs.com
- CVE-2016-1000236
- CWE-362
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime - CVE-2021-29445
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-cjs-runtime - CVE-2021-29446
- browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack - CVE-2023-46234
- Padding Oracle Attack due to Observable Timing Discrepancy in jose-browser-runtime - CVE-2021-29444
You might also like:
- Tags:
- npm
- cookie-signature
Anything's wrong? Let us know Last updated on January 11, 2023


