CVE-2016-5429
03.09.2016, 20:59
jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.Enginsight
Vendor | Product | Version |
---|---|---|
jose-php_project | jose-php | 𝑥 ≤ 2.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References