Логотип exploitDog
bind:CVE-2023-32691
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32691

Количество 2

Количество 2

nvd логотип

CVE-2023-32691

больше 2 лет назад

gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this comparison is not secure, an attacker can mount a side-channel timing attack to guess the password. As a workaround, this can be easily fixed using a constant time comparing function such as `crypto/subtle`'s `ConstantTimeCompare`.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-qjrq-hm79-49ww

больше 2 лет назад

ginuerzh/gost vulnerable to Timing Attack

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-32691

gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this comparison is not secure, an attacker can mount a side-channel timing attack to guess the password. As a workaround, this can be easily fixed using a constant time comparing function such as `crypto/subtle`'s `ConstantTimeCompare`.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qjrq-hm79-49ww

ginuerzh/gost vulnerable to Timing Attack

CVSS3: 5.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу