Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30443
HistoryMay 14, 2021 - 10:23 p.m.

Information Disclosure

2021-05-1422:23:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.004 Low

EPSS

Percentile

72.4%

prosody is vulnerable to information disclosure. The vulnerability exists as it does not use a constant-time algorithm for comparing secret strings when running under Lua 5.2 or later, allowing timing attacks to reveal the contents of secret strings.