Description


wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure information or impersonate an authed user.

Weaknesses



CWE-203

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-203

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

7.4 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-13T05:15:11.080Z

2 years ago

Last modified

2025-04-09T12:15:23.850Z

9 months ago