
We found results for “”
CVE-2024-47178
Good to know:


Date: September 30, 2024
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
Language: JS
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Observable Timing Discrepancy
CWE-208Top Fix

Upgrade Version
Upgrade to version dreamfactory/df-api-docs-ui - 1.1.0;tiitoo/symfony3-nodesjssocket - stable;tiitoo/symfony3-nodesjssocket - no_fix;genoboo - 0.4.3;reactorcoder/symfony2-nodesocket - stable;reactorcoder/symfony2-nodesocket - no_fix;Ncapsulate.Karma - no_fix;z4a-dotnet-scaffold - 1.0.0.2;genenotebook - no_fix;basic-auth-connect - 1.1.0;org.webjars.npm:bourbon-neat:2.1.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |