Description
All versions of parsel use an insecure cryptography algorithm. The package uses aes-256-cbc without integrity checks, which renders the ciphertext vulnerable to bit-flipping attacks.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Insecure Cryptography Algorithm in parsel and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Insecure Cryptography Algorithm in simple-crypto-js - Vulnerability
- @nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys - Vulnerability
- Hardcoded Initialization Vector in parsel - Vulnerability
- Insecure Default Configuration in tesseract.js - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


