Vulnerabilities > CVE-2024-25191 - Information Exposure Through Discrepancy vulnerability in Zihanggao PHP-Jwt 1.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |