Skip to content

トピトピニュース

Header Image
Archive

Month: September 2019

1 Post

Featured

Posted byGitHub
[org.apache.tapestry:tapestry-core] Timing attack on HMAC signature comparison in Apache Tapestry

[org.apache.tapestry:tapestry-core] Timing attack on HMAC signature comparison in Apache Tapestry

  • Posted inCRITICAL
  • Posted byGitHub
  • 09/27/201910/05/2022

The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side channel for the comparison of the HMAC signatures. This could lead to remote code execution if an attacker is able to determine the corr…

トピトピニュース
WordPress theme by componentz

Archives

2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Hit enter to search or ESC to close