Description
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
Remediation
References
https://github.com/vdemedes/secure-compare/pull/1
https://nodesecurity.io/advisories/50
Related Vulnerabilities
CVE-2020-7729 Vulnerability in maven package org.webjars.npm:grunt
CVE-2016-5018 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2021-4260 Vulnerability in npm package oils
CVE-2019-15302 Vulnerability in npm package cryptpad
CVE-2015-5298 Vulnerability in maven package org.jenkins-ci.plugins:google-login