QID 995795
Date Published: 2023-11-01
QID 995795: NodeJs (Npm) Security Update for generator-jhipster (GHSA-4gpm-r23h-gprw)
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4gpm-r23h-gprw for updates and patch information.
Vendor References
- GHSA-4gpm-r23h-gprw -
github.com/advisories/GHSA-4gpm-r23h-gprw
CVEs related to QID 995795
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4gpm-r23h-gprw | generator-jhipster |
|