Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35788
HistoryJun 01, 2022 - 3:18 p.m.

Timing Attack

2022-06-0115:18:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
34

0.001 Low

EPSS

Percentile

46.7%

firefox-esr is vulnerable to timing attack. An attacker allows to send a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals.