Описание
Timing side channel vulnerability in UIDL request handler in Vaadin 7 and 8
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack
Пакеты
com.vaadin:vaadin-bom
>= 7.0.0, < 7.7.24
7.7.24
com.vaadin:vaadin-bom
>= 8.0.0, < 8.12.3
8.12.3
com.vaadin:vaadin-server
>= 7.0.0, < 7.7.24
7.7.24
com.vaadin:vaadin-server
>= 8.0.0, < 8.12.3
8.12.3
Связанные уязвимости
Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7.7.23 (Vaadin 7.0.0 through 7.7.23), and 8.0.0 through 8.12.2 (Vaadin 8.0.0 through 8.12.2) allows attacker to guess a security token via timing attack