Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20913
HistoryJul 29, 2019 - 12:08 a.m.

Information Disclosure

2019-07-2900:08:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

52.8%

openjdk is vulnerable to information disclosure. It was discovered that the ChaCha20Cipher implementation in the Security component of OpenJDK used non-constant time comparison for comparing tags. A remote attacker could possible use the flaw to leak information about decryption state using the timing information.