CVE-2015-20110
Summary
| CVE | CVE-2015-20110 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-31 03:15:00 UTC |
| Updated | 2023-11-08 17:39:00 UTC |
| Description | JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fixed timing attack vulnerability in TokenProvider #2095 · jhipster/generator-jhipster@79fe562 · GitHub | MISC | github.com | |
| Comparing v2.22.0...v2.23.0 · jhipster/generator-jhipster · GitHub | MISC | github.com | |
| Security: TokenProvider vulnerable to timing attacks · Issue #2095 · jhipster/generator-jhipster · GitHub | MISC | github.com | |
| Merge pull request #2096 from maklemenz/tokenprovider-timingattack · jhipster/generator-jhipster@7c49ab3 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995795 NodeJs (Npm) Security Update for generator-jhipster (GHSA-4gpm-r23h-gprw)