DRSTEVE Crypt::Password是DRSTEVE个人开发者的一款密码处理模块。 DRSTEVE Crypt::Password 0.28及之前版本存在侧信道信息泄露漏洞,该漏洞源于check_password方法使用内置的eq运算符,容易受到计时攻击,攻击者可通过时间差异猜测底层哈希。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| DRSTEVE | Crypt::Password | ≤ 0.28 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DRSTEVE | Crypt::Password | 0 ~ 0.28 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet