Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rhonabwy 安全漏洞
Vulnerability Description
Rhonabwy是加拿大Nicolas Mora个人开发者的一个 Javascript 对象签名和加密 (JOSE) 库。 Rhonabwy 1.1.13及之前版本存在安全漏洞,该漏洞源于HMAC签名验证使用了strcmp函数函数,导致存在安全漏洞。
CVSS Information
N/A
Vulnerability Type
N/A