Vulnerabilities/

Hardcoded Initialization Vector in parsel

Severity:
High

Description

All versions of parsel have a default hardcoded initialization vector. In cases where the IV is not provided, the package defaults to a hardcoded IV which renders the cipher vulnerable to chosen plaintext attacks.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
parsel
Anything's wrong? Let us know Last updated on January 09, 2023