CVE-2024-25189
08.02.2024, 17:15
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.Enginsight
| Vendor | Product | Version |
|---|---|---|
| debian | debian_linux | 10.0 |
| libjwt | libjwt | 1.15.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases