Логотип exploitDog
bind:CVE-2017-3156
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-3156

Количество 3

Количество 3

redhat логотип

CVE-2017-3156

почти 9 лет назад

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2017-3156

больше 8 лет назад

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-qc2p-q7x9-v64p

больше 3 лет назад

Covert Timing Channel in Apache CXF

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-3156

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 5.3
13%
Средний
почти 9 лет назад
nvd логотип
CVE-2017-3156

The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

CVSS3: 7.5
13%
Средний
больше 8 лет назад
github логотип
GHSA-qc2p-q7x9-v64p

Covert Timing Channel in Apache CXF

CVSS3: 7.5
13%
Средний
больше 3 лет назад

Уязвимостей на страницу