@boxyhq/saml-jackson is vulnerable to Timing Attacks
55
Medium Risk
Affected versions of this package are affected by unsafe authentication and secret comparisons due to the lack of cryptographic comparison safe methods usage, resulting in noticeable timing discrepancies when handling user login specifically. Attackers can exploit these differences by measuring response times and error variations, which may allow them to infer credentials or keys. This vulnerability can lead to unauthorized access, privilege escalation, or user enumeration.
You are affected if you are using a version that falls within the vulnerable range.
@boxyhq/saml-jackson is vulnerable to Timing Attacks in versions 0.4.1 - 1.38.0.
Upgrade the @boxyhq/saml-jackson library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant