Vulnerabilities/

Insecure Cryptography Algorithm in simple-crypto-js

Severity:
Medium

Description

Versions of simple-crypto-js prior to 2.3.0 use AES-CBC with PKCS#7 padding, which is vulnerable to padding oracle attacks. This may allow attackers to break the encryption and access sensitive data.

Recommendation

Update the simple-crypto-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
simple-crypto-js
Anything's wrong? Let us know Last updated on April 17, 2023

This issue is available in SmartScanner Professional

See Pricing