Lucene search

K
prionPRIOn knowledge basePRION:CVE-2016-7037
HistoryJan 23, 2017 - 9:59 p.m.

Design/Logic Flaw

2017-01-2321:59:00
PRIOn knowledge base
www.prio-n.com
1

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.8%

The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signatures via a timing attack.

CPENameOperatorVersion
jwtle1.0.2

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

48.8%

Related for PRION:CVE-2016-7037