github.com/hashicorp/cap is vulnerable to Observable Timing Discrepancy
15
Low Risk
Affected versions of this package are vulnerable to timing attacks due to the use of a non-constant-time hash comparison in the verifyHashClaim function of the OIDC implementation. This flaw may allow attackers to infer valid hash values through response time analysis, potentially compromising the integrity of the verification process.
You are affected if you are using a version that falls within the vulnerable range.
github.com/hashicorp/cap is vulnerable to Observable Timing Discrepancy in versions 0.1.0 - 0.9.0.
Upgrade the github.com/hashicorp/cap library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant