CVE-2024-47178
- Reference to the description:
- Description:
- basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
- Last updated date:
- 11/15/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 11/15/2024
- Reference url to background
https://github.com/expressjs/basic-auth-connect/security/advisories/GHSA-7p89-p6hx-q4fw