VDB
Sign up
HIGH7.5

GHSA-4gpm-r23h-gprw

generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character

Quick fix

GHSA-4gpm-r23h-gprw — generator-jhipster: upgrade to the fixed version with the command below.

npm install generator-jhipster@2.23.0

Details

JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/generator-jhipster
Introduced in: 0Fixed in: 2.23.0
Fixnpm install generator-jhipster@2.23.0

References