—
GO-2023-1294
easy-scrypt Observable Timing Discrepancy vulnerability in github.com/agnivade/easy-scrypt
Quick fix
GO-2023-1294 — github.com/agnivade/easy-scrypt: upgrade to the fixed version with the command below.
go get github.com/agnivade/easy-scrypt@v1.0.0Details
easy-scrypt Observable Timing Discrepancy vulnerability in github.com/agnivade/easy-scrypt
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/agnivade/easy-scrypt
Introduced in:
0Fixed in: 1.0.0Fix
go get github.com/agnivade/easy-scrypt@v1.0.0References
- https://github.com/advisories/GHSA-r894-5r7v-7rx3[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2014-125055[ADVISORY]
- https://github.com/agnivade/easy-scrypt/commit/477c10cf3b144ddf96526aa09f5fdea613f21812[FIX]
- https://github.com/agnivade/easy-scrypt/releases/tag/v1.0.0[WEB]
- https://vuldb.com/?ctiid.217596[WEB]
- https://vuldb.com/?id.217596[WEB]