A time-sensitive equality check on the JWT signature in the JsonWebToken.validate method in main/scala/authentikat/jwt/JsonWebToken.scala in authentikat-jwt (aka com.jason-goodwin/authentikat-jwt) version 0.4.5 and earlier allows the supplier of a JWT token to guess bit after bit of the signature by repeating validation requests.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T21:13:49.152Z

Reserved: 2018-03-17T00:00:00

Link: CVE-2017-18239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-18T03:29:00.213

Modified: 2024-11-21T03:19:39.340

Link: CVE-2017-18239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.