Skip to content
This repository has been archived by the owner on Feb 25, 2019. It is now read-only.

Insecure dependencies - HMAC flaw #372

Open
bjamesvERT opened this issue Apr 4, 2018 · 0 comments
Open

Insecure dependencies - HMAC flaw #372

bjamesvERT opened this issue Apr 4, 2018 · 0 comments

Comments

@bjamesvERT
Copy link

passport-saml 0.15.0 has a number of remotely-exploitable security defects, including possible HMAC key recovery

https://rdist.root.org/2010/07/19/exploiting-remote-timing-attacks/

https://snyk.io/test/github/anvilresearch/connect.git?severity=high&severity=medium&severity=low

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant