CVE-2015-20110
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.
| Vendor | n/a |
| Product | n/a |
| Published | Oct 31, 2023 |
| Last Updated | Sep 6, 2024 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new unknown vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a
References
github.com: https://github.com/jhipster/generator-jhipster/issues/2095 github.com: https://github.com/jhipster/generator-jhipster/commit/7c49ab3d45dc4921b831a2ca55fb1e2a2db1ee25 github.com: https://github.com/jhipster/generator-jhipster/commit/79fe5626cb1bb80f9ac86cf46980748e65d2bdbc github.com: https://github.com/jhipster/generator-jhipster/compare/v2.22.0...v2.23.0