Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3907

Опубликовано: 05 дек. 2022
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clerk:clerk.io:*:*:*:*:*:wordpress:*:*
Версия до 4.0.0 (исключая)

EPSS

Процентиль: 68%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 7.5
github
около 3 лет назад

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

EPSS

Процентиль: 68%
0.00583
Низкий

7.5 High

CVSS3

Дефекты

CWE-203