CVE-2022-3907
05.12.2022, 17:15
The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.Enginsight
Vendor | Product | Version |
---|---|---|
clerk | clerk.io | 𝑥 < 4.0.0 |
𝑥
= Vulnerable software versions