CVE-2015-10004 Information
Dec 28, 2022
cve
Description
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection an attacker may use this to determine the expected HMAC.
Reference
https://github.com/robbert229/jwt/commit/ca1404ee6e83fcbafb66b09ed0d543850a15b654 https://pkg.go.dev/vuln/GO-2020-0023 https://github.com/robbert229/jwt/issues/12
Share on: