cve/2024/CVE-2024-47178.md
2025-09-29 21:09:30 +02:00

18 lines
760 B
Markdown

### [CVE-2024-47178](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47178)
![](https://img.shields.io/static/v1?label=Product&message=basic-auth-connect&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%201.1.0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-208%3A%20Observable%20Timing%20Discrepancy&color=brightgreen)
### Description
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds