Vulnerability GHSA-4gpm-r23h-gprw

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 years ago
October 31, 2023 at 03:31 AM UTC
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character
0.0.1 - 2.22.0
0.0.1 - 2.22.0

Summary

generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character

Details

JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

Impacted packages

Timeline

Published
2 years ago
October 31, 2023 at 03:31 AM UTC
Fixed (2.23.0)
Unknown
Unknown
Last Modified
2 years ago
November 08, 2023 at 06:41 PM UTC