PT-2023-31575 · Unknown+1 · Faye-Websocket.Js+1

Kelsey Tian

·

Published

2023-12-21

·

Updated

2023-12-29

·

CVE-2023-50475

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions bcoin versions 2.2.0
Description An issue was discovered that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component vendorfaye-websocket.js. This issue affects the bsock component.
Recommendations For version 2.2.0, consider disabling the use of weak hashing algorithms in the vendorfaye-websocket.js component until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2023-50475
GHSA-JJ93-39PF-7MCF

Affected Products

Bcoin
Faye-Websocket.Js