CVE-2015-10004 Information

Description

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection an attacker may use this to determine the expected HMAC.

Reference

https://github.com/robbert229/jwt/commit/ca1404ee6e83fcbafb66b09ed0d543850a15b654 https://pkg.go.dev/vuln/GO-2020-0023 https://github.com/robbert229/jwt/issues/12

Share on: