CVE-2024-25189
EUVD-2024-2252508.02.2024, 17:15
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 10.0 |
| libjwt | libjwt | 1.15.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases