{"id":"CVE-2024-47178","summary":"basic-auth-connect's callback uses time unsafe string comparison","details":"basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect \u003c 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.","aliases":["GHSA-7p89-p6hx-q4fw"],"modified":"2026-07-11T03:55:27.607425556Z","published":"2024-09-30T15:09:59.513Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47178.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47178.json"},{"type":"ADVISORY","url":"https://github.com/expressjs/basic-auth-connect/security/advisories/GHSA-7p89-p6hx-q4fw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47178"},{"type":"FIX","url":"https://github.com/expressjs/basic-auth-connect/commit/bac1e6a8530e1efd0028800b9b588a37adb0d203"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/expressjs/basic-auth-connect","events":[{"introduced":"0"},{"fixed":"45decb39d56845cc1f122065f4496168c6173339"},{"fixed":"bac1e6a8530e1efd0028800b9b588a37adb0d203"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:expressjs:basic-auth-connect:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.1.0"}]}}],"versions":["1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47178.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}