PT-2023-13035 · Unknown · Wildfly Elytron

CVE-2022-3143

·

Publicado

2023-01-11

·

Atualizado

2023-01-25

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wildfly-elytron (affected versions not specified)
Description A flaw was found in Wildfly-elytron, where it uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks. This allows an attacker to access secure information or impersonate an authenticated user. To compare values securely, java.security.MessageDigest.isEqual should be used instead.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider replacing java.util.Arrays.equals with java.security.MessageDigest.isEqual to securely compare values and minimize the risk of exploitation.

Exploit

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-3143
GHSA-JMJ6-P2J9-68CP
RHSA-2023:0552
RHSA-2023:0553
RHSA-2023:0554
RHSA-2025:9582
RHSA-2025:9583

Produtos afetados

Wildfly Elytron