@unit-finance/unit-node-sdk is vulnerable to Observable Timing Discrepancy
20
Low Risk
Affected versions of this package are vulnerable to a Timing Attack in the webhook signature verification function due to a non-constant-time string comparison. The vulnerable code used a standard equality operator to compare the expected and provided HMAC digests, which allows an attacker to exploit microscopic timing differences in the comparison operation. By repeatedly submitting forged signatures and measuring the server's response time, an attacker could gradually deduce the correct HMAC value character by character.
You are affected if you are using a version that falls within the vulnerable range.
@unit-finance/unit-node-sdk is vulnerable to Observable Timing Discrepancy in versions 0.8.13 - 1.3.4.
Upgrade the @unit-finance/unit-node-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant