Lucene search

K

Bearer-Auth Security Vulnerabilities

cve
cve

CVE-2022-31142

@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one valid bearer token. According to the corresponding RFC 6750, t...

7.5CVSS

7.4AI Score

0.001EPSS

2022-07-14 07:15 PM
37
4