CVE-2016-10535
Timing Attack in csrf-lite
EPSS 0.30%
描述
Affected versions of `csrf-lite` are vulnerable to timing attacks as a result of testing CSRF tokens via a fail-early comparison instead of a constant-time comparison. Timing attacks remove the exponential increase in entropy gained from increased secret length, by providing per-character feedback on the correctness of a guess via miniscule timing differences. Under favorable network conditions, an attacker can exploit this to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the timing attack not present. ## Recommendation Update to version 0.1.2 or later.
如何修補 CVE-2016-10535
要修補 CVE-2016-10535,請將受影響套件升級到下列已修補版本。
- —升級至 0.1.2 或更新版本
CVE-2016-10535 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.1.2