Timing Attack Vulnerability in JHipster Generator by JHipster
CVE-2015-20110

7.5HIGH

Key Information:

Vendor

Jhipster

Status
Vendor
CVE Published:
31 October 2023

What is CVE-2015-20110?

The JHipster generator-jhipster prior to version 2.23.0 is susceptible to a timing attack on the validateToken function. This vulnerability arises from a string comparison that terminates upon detecting the first mismatched character. Consequently, attackers can exploit this flaw by brute-forcing the token one character at a time, thereby narrowing the search to a manageable set of guesses based on the token length and available character set. This presents a significant security risk, making it feasible to guess valid tokens with relative ease.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.