132.145.45.33 63 packages

Last scanned on Nov 24 at 01:36 PM
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
License
MIT
Footprint
8 KB
Vulnerabilities
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Affected versions >=0 <9.0.0
jsonwebtoken unrestricted key type could lead to legacy keys usage
Affected versions >=0 <9.0.0
jsonwebtoken has insecure input validation in jwt.verify function
Affected versions >=0 <9.0.0
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Affected versions >=0 <9.0.0
Matched Modules
Version distribution in production
66
8.5.0
66
8.5.1
4
8.2.1
4
8.2.2
4
8.4.0
3
8.2.0
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
semver 5.7.0 - 6.3.0Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
debug 4.3.0 - 4.3.1Outdated
Lightweight debugging utility for Node.js and the browser
ms 2.1.2 - 2.1.3
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
inherits 2.0.3 - 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
@babel/runtime 7.9.6 - 7.20.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
axios 0.21.4Outdated
Promise based HTTP client for the browser and node.js
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
core-js 3.7.0 - 3.10.0Outdated
Standard library
util 0.10.0 - 0.12.5
Node.js's util module for all engines
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
lodash.isboolean 3.0.1 - 3.0.3
The lodash method `_.isBoolean` exported as a module.
asn1.js 5.2.0 - 5.4.1
ASN.1 encoder and decoder
lodash.includes 4.0.1 - 4.1.2Outdated
The lodash method `_.includes` exported as a module.
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
elliptic 6.5.4Outdated
EC cryptography
lodash.isnumber 3.0.1 - 3.0.3
The lodash method `_.isNumber` exported as a module.
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
des.js 1.0.1Outdated
DES implementation
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
cipher-base 1.0.4
abstract base class for crypto-streams
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
socket.io-parser 4.0.1 - 4.1.1Outdated
socket.io protocol parser
rauchg
darrachequesne
engine.io-parser 4.0.1 - 4.0.3Outdated
Parser for the client for the realtime Engine
rauchg
darrachequesne
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
vue 1.0.9 - 2.7.13Outdated
The progressive JavaScript framework for building modern web UI.
socket.io-client 4.0.0 - 4.0.1Outdated
Realtime application framework client
base64-arraybuffer 0.1.0 - 0.1.4Outdated
Encode/decode base64 data into ArrayBuffers
niklasvh
niklasvh
engine.io-client 5.0.0Outdated
Client for the realtime Engine
rauchg
darrachequesne
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
yeast 0.1.2
Tiny but linear growing unique id generator
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
idb-keyval 5.1.0 - 5.1.5Outdated
A super-simple-small keyval store built on top of IndexedDB
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
react-amphtml 3.0.0 - 4.0.2
Use amphtml components inside your React apps easily!
dfrankland
dfrankland