CVE-2015-20110: High severity jhipster vulnerability
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2015-20110.
What is the severity of CVE-2015-20110?
The severity of CVE-2015-20110 is not specified in the provided information.
How does CVE-2015-20110 work?
CVE-2015-20110 allows a timing attack against validateToken by brute forcing one character at a time and observing the timing.
How can I fix CVE-2015-20110?
To fix CVE-2015-20110, update to version 2.23.0 or later of generator-jhipster.
Where can I find more information about CVE-2015-20110?
You can find more information about CVE-2015-20110 in the references provided: [link1], [link2], [link3].