Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-2418

CVE-2022-3143 wildfly-elytron: possible timing attacks via use of unsafe comparator

XMLWordPrintable

      WildFly Elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. java.security.MessageDigest.isEqual should be used instead to compare values securely. An attacker could possibly use this vulnerability to access secure information or impersonate an authenticated user.

      This issue will be handled via a bunch of sub-tasks.

              fjuma1@redhat.com Farah Juma
              fjuma1@redhat.com Farah Juma
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: