GHSA-qc2p-q7x9-v64p
HIGHCVE-2017-3156The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.
- Affected
- <= 3.0.12, >= 3.1.0, <= 3.1.9
- Fixed in
- 3.0.13
- Weakness
- CWE-385
- Published
- 2022-05-13
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference