Mojolicious module vulnerable to secure_compare timing attacks
CVE-2020-36829
7.5HIGH
What is CVE-2020-36829?
The Mojolicious Perl module, prior to version 8.65, is susceptible to timing attacks that exploit its secure_compare function. This vulnerability allows attackers to infer the length of secret strings through manipulated timing discrepancies. Only versions after 1.74 are impacted, posing a risk for applications relying on this module for secure string comparisons, thus necessitating immediate attention for any deployments using affected versions.
