{"id":"GHSA-pqj5-37xf-x5gc","summary":"blinksocks has weak encryption algorithms","details":"An issue was discovered in blinksocks version 3.3.8, allows remote attackers to obtain sensitive information via weak encryption algorithms in the component `/presets/ssr-auth-chain.js`.","aliases":["CVE-2023-50481"],"modified":"2023-12-21T18:28:09.707713Z","published":"2023-12-21T12:30:29Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-12-21T18:12:37Z","nvd_published_at":"2023-12-21T11:15:08Z","cwe_ids":[]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50481"},{"type":"WEB","url":"https://github.com/blinksocks/blinksocks/issues/108"},{"type":"PACKAGE","url":"https://github.com/blinksocks/blinksocks"},{"type":"WEB","url":"https://github.com/tianjk99/Cryptographic-Misuses/blob/main/CVE-2023-50481.md"}],"affected":[{"package":{"name":"blinksocks","ecosystem":"npm","purl":"pkg:npm/blinksocks"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.3.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-pqj5-37xf-x5gc/GHSA-pqj5-37xf-x5gc.json"}}],"schema_version":"1.9.0"}