CVE-2024-25190

l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Configurations

Configuration 1 (hide)

cpe:2.3:a:glitchedpolygons:l8w8jwt:2.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-08 17:15

Updated : 2024-11-21 09:00


NVD link : CVE-2024-25190

Mitre link : CVE-2024-25190

CVE.ORG link : CVE-2024-25190


JSON object : View

Products Affected

glitchedpolygons

  • l8w8jwt
CWE
CWE-203

Observable Discrepancy