jsrsasign is vulnerable to Observable Timing Discrepancy
24
Low Risk
Observable timing discrepancies in HMAC-based JSON Web Signature verification in jsrsasign allowed signature comparisons to be performed using direct string equality rather than a constant-time routine. An attacker able to measure verification response times repeatedly could potentially infer valid signature bytes and forge HMAC-signed JWS tokens. Successful exploitation could result in authentication bypass, token forgery, or unauthorized access to protected resources relying on affected HS* signature verification paths.
You are affected if you are using a version that falls within the vulnerable range.
jsrsasign is vulnerable to Observable Timing Discrepancy in versions 4.10.0 - 11.1.2.
Upgrade the jsrsasign library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant