{"id":"GHSA-92vm-wfm5-mxvv","summary":"cookie-signature Timing Attack","details":"Affected versions of `cookie-signature` are vulnerable to timing attacks as a result of using a fail-early comparison instead of a constant-time comparison. \n\nTiming attacks remove the exponential increase in entropy gained from increased secret length, by providing per-character feedback on the correctness of a guess via miniscule timing differences.\n\nUnder favorable network conditions, an attacker can exploit this to guess the secret in no more than `charset*length` guesses, instead of `charset^length` guesses required were the timing attack not present. \n\n\n\n## Recommendation\n\nUpdate to 1.0.4 or later.","aliases":["CVE-2016-1000236"],"modified":"2023-11-01T04:46:29.456800Z","published":"2020-01-06T18:44:10Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-12-27T22:19:47Z","nvd_published_at":null,"cwe_ids":["CWE-362"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000236"},{"type":"WEB","url":"https://github.com/tj/node-cookie-signature/commit/2c4df6b6cee540f30876198cd0b5bebf28528c07"},{"type":"WEB","url":"https://github.com/tj/node-cookie-signature/commit/39791081692e9e14aa62855369e1c7f80fbfd50e"},{"type":"WEB","url":"https://github.com/tj/node-cookie-signature/commit/4cc5e21e7f59a4ea0b51cd5e9634772d48fab590"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=838618"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1371409"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-1000236"},{"type":"PACKAGE","url":"https://github.com/tj/node-cookie-signature"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2016-1000236"},{"type":"WEB","url":"https://travis-ci.com/nodejs/security-wg/builds/76423102"},{"type":"WEB","url":"https://www.mail-archive.com/secure-testing-team@lists.alioth.debian.org/msg06583.html"},{"type":"WEB","url":"https://www.npmjs.com/advisories/134"}],"affected":[{"package":{"name":"cookie-signature","ecosystem":"npm","purl":"pkg:npm/cookie-signature"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-92vm-wfm5-mxvv/GHSA-92vm-wfm5-mxvv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}