Vulnerability GHSA-4gpm-r23h-gprw
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 years ago
October 31, 2023 at 03:31 AM UTC
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character
0.0.1 - 2.22.0
0.0.1 - 2.22.0
Summary
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character
Details
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
6 hours ago
JHipster: SQL Injection in the Parameter of JHipster-Generated Reactive (WebFlux + R2DBC) Applicationssort
7.0.0 - 9.3.0 GHSA-r223-96jv-q533
7.0.0 - 9.3.0 GHSA-r223-96jv-q533
High Risk
6 hours ago
JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opened as Same-Origin Blob
0.0.1 - 9.3.0 GHSA-9ffp-22j7-56r2
0.0.1 - 9.3.0 GHSA-9ffp-22j7-56r2
High Risk
4 years ago
SQL Injection when creating an application with Reactive SQL backend
7.0.0 - 7.8.0 GHSA-qjmq-8hjr-qcv6
7.0.0 - 7.8.0 GHSA-qjmq-8hjr-qcv6
High Risk
7 years ago
High severity vulnerability that affects generator-jhipster
0.0.1 - 6.3.0 GHSA-mc84-xr9p-938r
0.0.1 - 6.3.0 GHSA-mc84-xr9p-938r
Impacted packages
Timeline
Published
2 years ago
October 31, 2023 at 03:31 AM UTC
Fixed (2.23.0)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 06:41 PM UTC