wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure information or impersonate an authed user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-01-11T20:57:29.342Z
Updated: 2024-08-03T01:00:10.516Z
Reserved: 2022-09-06T19:26:59.538Z
Link: CVE-2022-3143
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-13T06:15:11.080
Modified: 2024-11-21T07:18:54.993
Link: CVE-2022-3143
Redhat