9.8
CVSSv3

CVE-2024-25191

Published: 08/02/2024 Updated: 15/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

Vulnerable Product Search on Vulmon Subscribe to Product

zihanggao php-jwt 1.0.0