Количество 2
Количество 2
CVE-2016-10535
csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the timing attack not present.
GHSA-hjhr-r3gq-qvp6
Timing Attack in csrf-lite
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-10535 csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the timing attack not present. | CVSS3: 5.9 | 0% Низкий | больше 7 лет назад | |
GHSA-hjhr-r3gq-qvp6 Timing Attack in csrf-lite | 0% Низкий | почти 7 лет назад |
Уязвимостей на страницу