Vulnerabilities/

Missing Cryptographic Step in cassproject

Severity:
Medium

Description

CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cryptographic keys that can allow a server administrator access to an account’s cryptographic keys. This affects CaSS servers using standalone username/password authentication, which uses a method that expects e2e cryptographic security of authorization credentials.

Recommendation

Update the cassproject package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
cassproject
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing