Vulnerabilities/

Insecure Cryptography Algorithm in parsel

Severity:
High

Description

All versions of parsel use an insecure cryptography algorithm. The package uses aes-256-cbc without integrity checks, which renders the ciphertext vulnerable to bit-flipping attacks.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
parsel
Anything's wrong? Let us know Last updated on January 09, 2023