First published: Thu Feb 08 2024(Updated: )
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bencollins Jwt C Library | =1.15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.