VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (798)

page 38 of 40
  • CVE-2024-50382MedOct 23, 2024
    risk 0.00cvss 5.9epss 0.01

    Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in AES-GCM. There is a branch instead of an XOR with carry. This was observed for Clang in LLVM 15 on RISC-V.

  • CVE-2024-45052MedSep 4, 2024
    risk 0.00cvss 5.3epss 0.01

    Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an unauthenticated attacker to determine the existence of valid usernames by…

  • CVE-2024-1544MedAug 27, 2024
    risk 0.00cvss 4.1epss 0.00

    Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The division used during the reduction estimates a factor q_e by dividing the upper two …

  • CVE-2024-37880HigJun 10, 2024
    risk 0.00cvss 7.5epss 0.01

    The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not…

  • CVE-2024-5124HigJun 6, 2024
    risk 0.00cvss 7.5epss 0.01

    A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the '=' operator in Python. This method of…

  • CVE-2024-0436MedFeb 26, 2024
    risk 0.00cvss 5.9epss 0.00

    Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request,…

  • CVE-2024-25714CriFeb 11, 2024
    risk 0.00cvss 9.8epss 0.01

    In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)

  • CVE-2023-6258HigJan 30, 2024
    risk 0.00cvss 8.1epss 0.01

    A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in a Bleichenbacher-like security flaw, potentially enabling a side-channel…

  • CVE-2024-23771CriJan 22, 2024
    risk 0.00cvss 9.8epss 0.01

    darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.

  • CVE-2023-40021MedAug 16, 2023
    risk 0.00cvss 5.3epss 0.01

    Oppia is an online learning platform. When comparing a received CSRF token against the expected token, Oppia uses the string equality operator (`==`), which is not safe against timing attacks. By repeatedly submitting invalid tokens, an attacker can brute-force the expected CSRF…

  • CVE-2023-32694MedMay 25, 2023
    risk 0.00cvss 4.8epss 0.00

    Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the secret key and forge…

  • CVE-2022-40482MedApr 25, 2023
    risk 0.00cvss 5.3epss 0.01

    The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the…

  • CVE-2023-0361HigFeb 15, 2023
    risk 0.00cvss 7.4epss 0.01

    A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the…

  • CVE-2023-0440MedJan 23, 2023
    risk 0.00cvss 5.3epss 0.01

    Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.

  • CVE-2022-4823LowDec 28, 2022
    risk 0.00cvss 3.1epss 0.01

    A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing discrepancy. It is possible to launch the…

  • CVE-2022-4087LowNov 21, 2022
    risk 0.00cvss 2.6epss 0.01

    A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure through discrepancy. The name…

  • CVE-2022-41914LowNov 16, 2022
    risk 0.00cvss 3.7epss 0.01

    Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did not run in constant time. Therefore, it…

  • CVE-2022-24784LowMar 25, 2022
    risk 0.00cvss 3.7epss 0.01

    Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually…

  • CVE-2021-44421MedMar 10, 2022
    risk 0.00cvss 5.5epss 0.00

    The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.

  • CVE-2022-22120MedJan 10, 2022
    risk 0.00cvss 5.3epss 0.01

    In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows…