QID 996721
Date Published: 2024-01-17
QID 996721: NodeJs (Npm) Security Update for @evershop/evershop (GHSA-32r3-57hp-cgfw)
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.9. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-32r3-57hp-cgfw for updates and patch information.
Vendor References
- GHSA-32r3-57hp-cgfw -
github.com/advisories/GHSA-32r3-57hp-cgfw
CVEs related to QID 996721
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-32r3-57hp-cgfw | @evershop/evershop |
|