CVE-2024-25189
published 2024-02-08CVE-2024-25189: libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.95%
57.8th percentile
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libjwt | < libjwt 1.10.2-1+deb12u1 (bookworm) | libjwt 1.10.2-1+deb12u1 (bookworm) |
| libjwt | libjwt | — | — |
| libjwt | libjwt | >= 0 < 1.10.2-1+deb11u1 | 1.10.2-1+deb11u1 |
| libjwt | libjwt | >= 0 < 1.10.2-1+deb12u1 | 1.10.2-1+deb12u1 |
| libjwt | libjwt | >= 0 < 1.17.0-2 | 1.17.0-2 |
| libjwt | libjwt | >= 0 < 1.17.0-2 | 1.17.0-2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-25189: libjwt - libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication,...
vendor_debian·2024·CVSS 9.8
CVE-2024-25189 [CRITICAL] CVE-2024-25189: libjwt - libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication,...
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
Scope: local
bookworm: resolved (fixed in 1.10.2-1+deb12u1)
bullseye: resolved (fixed in 1.10.2-1+deb11u1)
forky: resolved (fixed in 1.17.0-2)
sid: resolved (fixed in 1.17.0-2)
trixie: resolved (fixed in 1.17.0-2)
GHSA
GHSA-m5gq-732f-j9v6: libjwt 1
ghsa_unreviewed·2024-02-08
CVE-2024-25189 [CRITICAL] CWE-203 GHSA-m5gq-732f-j9v6: libjwt 1
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
OSV
CVE-2024-25189: libjwt 1
osv·2024-02-08·CVSS 9.8
CVE-2024-25189 [CRITICAL] CVE-2024-25189: libjwt 1
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-08
Published