Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc2p-q7x9-v64p

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Covert Timing Channel in Apache CXF

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Пакеты

Наименование

org.apache.cxf.karaf:apache-cxf

maven
Затронутые версииВерсия исправления

<= 3.0.12

3.0.13

Наименование

org.apache.cxf.karaf:apache-cxf

maven
Затронутые версииВерсия исправления

>= 3.1.0, <= 3.1.9

3.1.10

EPSS

Процентиль: 94%
0.1307
Средний

7.5 High

CVSS3

Дефекты

CWE-385

Связанные уязвимости

CVSS3: 5.3
redhat
почти 9 лет назад

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 7.5
nvd
больше 8 лет назад

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

EPSS

Процентиль: 94%
0.1307
Средний

7.5 High

CVSS3

Дефекты

CWE-385