CVE-2015-9238

CVE-2015-9238

secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.

Source: CVE-2015-9238

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다