Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-3156

Опубликовано: 10 авг. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:*
Версия до 3.0.12 (включая)
cpe:2.3:a:apache:cxf:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.8:*:*:*:*:*:*:*
cpe:2.3:a:apache:cxf:3.1.9:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.1307
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
redhat
почти 9 лет назад

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 7.5
github
больше 3 лет назад

Covert Timing Channel in Apache CXF

EPSS

Процентиль: 94%
0.1307
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo