Описание
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
A flaw was found in Plack-Middleware-Session. This vulnerability allows attackers to perform timing attacks on Hash-based Message Authentication Code (HMAC) comparisons.
Отчет
This vulnerability is rated Important for Red Hat products that use Plack::Middleware::Session. A timing attack on HMAC comparison could allow an attacker to infer sensitive information, potentially leading to session hijacking. Successful exploitation requires the ability to accurately measure response times, which may be challenging in typical network environments.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMA ...
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
7.5 High
CVSS3