Versions of express-basic-auth
prior to 1.1.7 are vulnerable to Timing Attacks. The package uses native string comparison instead of a constant time string comparison, which may lead to Timing Attacks. Timing Attacks can be used to increase the efficiency of brute-force attacks by removing the exponential increase in entropy gained from longer secrets.
Upgrade to version 1.1.7 or later.
{ "nvd_published_at": null, "severity": "LOW", "github_reviewed_at": "2019-06-06T09:51:04Z", "github_reviewed": true, "cwe_ids": [ "CWE-208" ] }