You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
And the elliptic dev seems to be aware of the issue but has no plans to fix it: indutny/elliptic#128.
Removing the crypto-browserify isn't feasible, it would break a lot of backwards compatibility, and alternatives like brix/crypto-jsseems to have the same vulnerability: brix/crypto-js#88 😞
The karma-typescript package has been flagged in my organization's compliance report since the elliptic npm package that it uses, is not recommended.
Description Provided: all versions of elliptic are vulnerable to Timing Attack through side-channels.
Hence wondering, if there is any plan to fix the vulnerability.
The text was updated successfully, but these errors were encountered: