Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40655
HistoryMay 24, 2023 - 4:08 a.m.

Timing Attack

2023-05-2404:08:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
timing attack
github.com/ginuerzh/gost
insecure secret comparison
authenticate function
auth.go

0.001 Low

EPSS

Percentile

48.7%

github.com/ginuerzh/gost is vulnerable to Timing Attacks. The vulnerability exists because the Authenticate function of auth.go does not properly compare sensitive secrets such as passwords, tokens and API keys using constant-time comparison, which allows an attacker to guess a secret by observing a difference in processing time for valid and invalid inputs.

CPENameOperatorVersion
github.com/ginuerzh/gostlev2.11.5

0.001 Low

EPSS

Percentile

48.7%

Related for VERACODE:40655