Beveiligingsadvies

CVE-2024-0436

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-02-25 16:25:11
Laatst bijgewerkt 2025-03-27 10:44:21
Toegewezen door @huntr_ai
CVSS-score 7.1
Status PUBLISHED

Beschrijving

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature making the attack less reliable to execute