github.com/getsops/sops/v3 is vulnerable to Observable Timing Discrepancy
47
Medium Risk
Affected versions of this package exhibit an observable timing discrepancy due to duplicated vulnerable code from github.com/hashicorp/vault (CVE-2023-25000). HashiCorp Vault’s Shamir secret sharing implementation relies on precomputed table lookups, making it susceptible to cache-timing attacks. An attacker with access to the host and the ability to monitor a large number of unseal operations via a side channel can significantly reduce the search space for brute-force recovery of Shamir shares.
You are affected if you are using a version that falls within the vulnerable range.
github.com/getsops/sops/v3 is vulnerable to Observable Timing Discrepancy in versions 3.0.0 - 3.9.4.
Upgrade the github.com/getsops/sops/v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant