Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-10031

Опубликовано: 09 дек. 2025
Источник: redhat
CVSS3: 7.5

Описание

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

A flaw was found in Plack-Middleware-Session. This vulnerability allows attackers to perform timing attacks on Hash-based Message Authentication Code (HMAC) comparisons.

Отчет

This vulnerability is rated Important for Red Hat products that use Plack::Middleware::Session. A timing attack on HMAC comparison could allow an attacker to infer sensitive information, potentially leading to session hijacking. Successful exploitation requires the ability to accurately measure response times, which may be challenging in typical network environments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1254
https://bugzilla.redhat.com/show_bug.cgi?id=2420282Plack-Middleware-Session: Plack-Middleware-Session: HMAC comparison timing attack vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 месяцев назад

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

CVSS3: 7.5
nvd
8 месяцев назад

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

CVSS3: 7.5
debian
8 месяцев назад

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMA ...

CVSS3: 7.5
github
8 месяцев назад

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

7.5 High

CVSS3