Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4674
HistoryJul 25, 2017 - 10:24 p.m.

Timing Attacks

2017-07-2522:24:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
1

0.001 Low

EPSS

Percentile

48.8%

Malcolm Fell jwt is vulnerable to timing attacks. The library does not compare hashes in constant time, which allows malicious users to use the timing of the request to progressively identify a valid hash.

CPENameOperatorVersion
emarref/jwtle1.0.2

0.001 Low

EPSS

Percentile

48.8%

Related for VERACODE:4674