Количество 2
Количество 2
CVE-2017-18239
A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
GHSA-3rhm-67j6-42jq
Exposure of Sensitive information in authentikat-jwt
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-18239 A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests. | CVSS3: 9.8 | 0% Низкий | почти 8 лет назад | |
GHSA-3rhm-67j6-42jq Exposure of Sensitive information in authentikat-jwt | CVSS3: 9.8 | 0% Низкий | около 7 лет назад |
Уязвимостей на страницу