Количество 2
Количество 2
CVE-2015-10004
около 3 лет назад
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.
CVSS3: 7.5
EPSS: Низкий
GHSA-5vw4-v588-pgv8
около 3 лет назад
robbert229/jwt's token validation methods vulnerable to a timing side-channel during HMAC comparison
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2015-10004 Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-5vw4-v588-pgv8 robbert229/jwt's token validation methods vulnerable to a timing side-channel during HMAC comparison | CVSS3: 7.5 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу
20