PT-2024-32459 · Unknown · Basic-Auth-Connect

Adamkorcz

·

Published

2024-09-30

·

Updated

2024-11-15

·

CVE-2024-47178

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions basic-auth-connect versions prior to 1.1.0
Description The issue concerns a timing-unsafe equality comparison in basic-auth-connect that can leak timing information. This comparison can potentially allow an attacker to observe differences in response times, which may lead to security issues. The problem has been fixed in version 1.1.0 of basic-auth-connect.
Recommendations For versions prior to 1.1.0, update to basic-auth-connect 1.1.0 to fix the timing information leak in Basic Auth middleware. As a temporary workaround, consider restricting access to the Basic Auth functionality until the update can be applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-47178
GHSA-7P89-P6HX-Q4FW

Affected Products

Basic-Auth-Connect