Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5141
HistorySep 20, 2017 - 6:51 a.m.

Timing Attacks

2017-09-2006:51:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.002 Low

EPSS

Percentile

65.0%

kohana/core is vulnerable to timing attacks. The library is vulnerable because it does not compare hashes in constant-time, which allows attackers to use the timing of the request to progressively identify a valid hash.

CPENameOperatorVersion
kohana/corele3.3.2

0.002 Low

EPSS

Percentile

65.0%