robrichards/xmlseclibs is vulnerable to Timing Attacks
60
Medium Risk
XMLSecurityKey::verifySignature() compares HMAC-SHA1 signatures with a non-constant-time comparison. Under favorable conditions this timing side channel can be used to recover a valid MAC byte by byte and forge a signature that verifies. The affected path also returned inconsistent truthy values rather than a strict result. The fix uses a constant-time comparison and returns a strict 1/0 result.
You are affected if you are using a version that falls within the vulnerable range and you verify HMAC-SHA1 signed XML from untrusted sources.
robrichards/xmlseclibs is vulnerable to Timing Attacks in versions 1.3.3 - 3.1.5.
Upgrade the robrichards/xmlseclibs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.