Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12800
HistoryJan 15, 2019 - 9:21 a.m.

Timing Attack

2019-01-1509:21:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.002 Low

EPSS

Percentile

55.5%

sinatra is vulnerable to timing attacks. This vulnerability is caused because the csrf tokens are not compared in constant time, allowing malicious users to guess the valid csrf tokens based on the time that a comparison takes.

CPENameOperatorVersion
pcseq0.9.137__13.el7_1.2
pcseq0.9.158__4.el7