Description
All versions of parsel have a default hardcoded initialization vector. In cases where the IV is not provided, the package defaults to a hardcoded IV which renders the cipher vulnerable to chosen plaintext attacks.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Hardcoded Initialization Vector in parsel and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Insecure Cryptography Algorithm in parsel - Vulnerability
- Insufficient Entropy in parsel - Vulnerability
- Flowise: Path Traversal in Vector Store basePath - Vulnerability
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function - CVE-2024-9506
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


