Lucene search

K
osvGoogleOSV:GHSA-V882-949X-6V28
HistoryMay 14, 2022 - 1:04 a.m.

SimpleSAMLphp allows timing side-channel attacks

2022-05-1401:04:04
Google
osv.dev
10
simplesamlphp
timing side-channel attacks
htpasswd authentication

EPSS

0.003

Percentile

70.0%

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.