GHSA-vjvw-wcmw-pr26

Suggest an improvement
Source
https://github.com/advisories/GHSA-vjvw-wcmw-pr26
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vjvw-wcmw-pr26/GHSA-vjvw-wcmw-pr26.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vjvw-wcmw-pr26
Published
2020-09-04T17:37:08Z
Modified
2020-08-31T19:00:10Z
Summary
Insufficient Entropy in parsel
Details

All versions of parsel use an insecure key derivation function. The package runs keys of arbitrary lengths through one round of SHA256 hashing for key stretching. This allows for the use of keys of insufficient entropy with inappropriate key stretching.

Recommendation

The package is deprecated and will not be updated. Consider using an alternative package.

Database specific
{
    "cwe_ids":  [
        "CWE-331"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T19:00:10Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / parsel

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vjvw-wcmw-pr26/GHSA-vjvw-wcmw-pr26.json"