Vulnerabilities > CVE-2024-47178 - Unspecified vulnerability in Expressjs Basic-Auth-Connect
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |