CVE Published: 27/12/2022 |
CVE Updated: 06/08/2024 |
CVE Year: 2015 Source: Go |
Vendor: github.com/robbert229/jwt |
Product: github.com/robbert229/jwt Status : PUBLISHED
CVE-2015-10004 Description
Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine the expected HMAC.