Lucene search

K
osvGoogleOSV:GHSA-Q8HG-PF8V-CXRV
HistoryMar 26, 2022 - 12:22 a.m.

Symfony Http-Kernel has non-constant time comparison in UriSigner

2022-03-2600:22:49
Google
osv.dev
16
symfony
http-kernel
non-constant
time comparison
urisigner
potential remote timing attack
vulnerability
software

EPSS

0.009

Percentile

82.4%

When checking the signature of an URI (an ESI fragment URL for instance), the URISigner did not used a constant time string comparison function, resulting in a potential remote timing attack vulnerability.

References