VYPR

Shrine

by shrinerb

Source repositories

CVEs (1)

  • CVE-2020-15237Oct 5, 2020
    risk 0.00cvss epss 0.01

    In Shrine before version 3.3.0, when using the `derivation_endpoint` plugin, it's possible for the attacker to use a timing attack to guess the signature of the derivation URL. The problem has been fixed by comparing sent and calculated signature in constant time, using…