First published: Thu Feb 08 2024(Updated: )
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zihanggao Php-jwt | =1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.