Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3476 | An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack. |
Github GHSA |
GHSA-h63v-hw6g-x8hp | Bit flip attack vulnerability in cookie-encrypter |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Dec 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-327 | |
| Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-11T20:45:11.118Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53441
Updated: 2024-12-11T20:36:09.469Z
Status : Deferred
Published: 2024-12-09T20:15:20.800
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-53441
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA