Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrvm-94fq-4hmv

Опубликовано: 05 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

EPSS

Процентиль: 68%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-203

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

EPSS

Процентиль: 68%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-203