Description
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
Remediation
References
https://github.com/vdemedes/secure-compare/pull/1
https://nodesecurity.io/advisories/50
Related Vulnerabilities
CVE-2017-11342 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2018-1999033 Vulnerability in maven package org.jenkins-ci.plugins:anchore-container-scanner
CVE-2021-23700 Vulnerability in npm package merge-deep2
CVE-2021-21672 Vulnerability in maven package org.jenkins-ci.plugins:seleniumhtmlreport