ZeroHour

CVE-2022-3143

CVSS 3.1
7.4 high
EPSS
<1%p46
Published
()
Modified
Description

wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure information or impersonate an authed user.

Vendors
redhat
Products
wildfly elytron, jboss enterprise application platform
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.