mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-29 01:31:20 +00:00
33 lines
1.1 KiB
JSON
33 lines
1.1 KiB
JSON
{
|
|
"id": "CVE-2020-36829",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2024-04-08T00:15:07.840",
|
|
"lastModified": "2024-06-30T11:15:09.780",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "El m\u00f3dulo Mojolicious anterior a 8.65 para Perl es vulnerable a ataques de sincronizaci\u00f3n Secure_compare que permiten a un atacante adivinar la longitud de una cadena secreta. S\u00f3lo se ven afectadas las versiones posteriores a la 1.74."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"references": [
|
|
{
|
|
"url": "https://github.com/mojolicious/mojo/issues/1599",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://github.com/mojolicious/mojo/pull/1601",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00025.html",
|
|
"source": "cve@mitre.org"
|
|
}
|
|
]
|
|
} |