Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.50%
Published
May 31, 2018
Modified
Nov 20, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
Weaknesses (CWE)
Affected Products (1)
References (4)