wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. To compare values securely, use java.security.MessageDigest.isEqual instead. This flaw allows an attacker to access secure information or impersonate an authed user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-01-11T20:57:29.342Z

Updated: 2024-08-03T01:00:10.516Z

Reserved: 2022-09-06T19:26:59.538Z

Link: CVE-2022-3143

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-01-13T06:15:11.080

Modified: 2023-01-25T20:38:36.133

Link: CVE-2022-3143

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-09-06T00:00:00Z

Links: CVE-2022-3143 - Bugzilla