hwi/oauth-bundle is vulnerable to Generation of Weak Initialization Vector (IV)
28
Low Risk
Affected versions of this package contain a security misconfiguration that generates nonces using MD5, relying solely on predictable time-based values without any cryptographic randomness. An attacker could exploit this vulnerability by predicting or brute-forcing these nonces, especially in situations where multiple nonces are generated within short time intervals, which significantly reduces entropy. This predictability could enable replay attacks, token forgery, or session hijacking, allowing an attacker to craft requests with valid-looking nonces.
You are affected if you are using a version that falls within the vulnerable range.
hwi/oauth-bundle is vulnerable to Generation of Weak Initialization Vector (IV) in versions 1.2.0 - 2.3.0.
Upgrade the hwi/oauth-bundle library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant