Описание
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| php-jwt | removed | package |
EPSS
Процентиль: 22%
0.00072
Низкий
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 2 года назад
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVSS3: 9.8
nvd
почти 2 года назад
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVSS3: 9.8
github
почти 2 года назад
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
EPSS
Процентиль: 22%
0.00072
Низкий