Nixpkgs security tracker

Login with GitHub

Suggestion detail

Untriaged
created 2 weeks, 5 days ago Activity log
  • Created suggestion
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

Affected products

Catalyst-Plugin-Authentication
  • =<0.10024

Matching in nixpkgs