CVE-2015-9238
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.5%
probabilidad de explotación
1.5%top 28% de las CVE
explotación observada
noninguna fuente lo reporta
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
Productos afectados
HackerOne · secure-compare node module