Vulnerabilities/

Server secret was included in static assets and served to clients

Severity:
High

Description

Server JWT signing secret was included in static assets and served to clients.

This ALLOWS Flood’s builtin authentication to be bypassed.

Recommendation

Update the flood package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
flood
Anything's wrong? Let us know Last updated on January 06, 2023

This issue is available in SmartScanner Professional

See Pricing