National Cyber Warfare Foundation (NCWF)

CVE-2024-47178


0 user ratings
2024-09-19 00:00:00
milo
CVEs

 - archive -- 

CVE-2024-47178

Date: 2024-09-19

CVE Link

basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.



References:



Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
CVEs



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.