An issue was discovered in NPMs package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as secret. A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
The product contains hard-coded credentials, such as a password or cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evershop | Evershop | 1.0.0-beta (including) | 1.0.0-beta (including) |
Evershop | Evershop | 1.0.0-beta1 (including) | 1.0.0-beta1 (including) |
Evershop | Evershop | 1.0.0-beta2 (including) | 1.0.0-beta2 (including) |
Evershop | Evershop | 1.0.0-beta3 (including) | 1.0.0-beta3 (including) |
Evershop | Evershop | 1.0.0-beta4 (including) | 1.0.0-beta4 (including) |
Evershop | Evershop | 1.0.0-beta5 (including) | 1.0.0-beta5 (including) |
Evershop | Evershop | 1.0.0-rc1 (including) | 1.0.0-rc1 (including) |
Evershop | Evershop | 1.0.0-rc2 (including) | 1.0.0-rc2 (including) |
Evershop | Evershop | 1.0.0-rc3 (including) | 1.0.0-rc3 (including) |
Evershop | Evershop | 1.0.0-rc5 (including) | 1.0.0-rc5 (including) |
Evershop | Evershop | 1.0.0-rc6 (including) | 1.0.0-rc6 (including) |
Evershop | Evershop | 1.0.0-rc7 (including) | 1.0.0-rc7 (including) |
There are two main variations: