GHSA-h9x2-5rm7-x4gm

Suggest an improvement
Source
https://github.com/advisories/GHSA-h9x2-5rm7-x4gm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h9x2-5rm7-x4gm
Aliases
  • CVE-2015-9238
Published
2019-06-03T17:28:23Z
Modified
2023-11-08T03:58:04Z
Summary
Insecure Comparison in secure-compare
Details

Versions of secure-compare prior to 3.0.1 are affected by a vulnerability that results in the package always returning true when comparing two strings of the same length, despite differences in the contents of those strings.

Recommendation

Upgrade to version 3.0.1 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-697"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-03T17:22:37Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / secure-compare

Package

Name
secure-compare
View open source insights on deps.dev
Purl
pkg:npm/secure-compare

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json"