Miggo Logo

CVE-2022-3143: Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator

7.4

CVSS Score
3.1

Basic Information

EPSS Score
0.39392%
Published
1/13/2023
Updated
1/25/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.wildfly.security:wildfly-elytronmaven< 1.15.15.Final1.15.15.Final
org.wildfly.security:wildfly-elytronmaven>= 1.16.0.CR1, < 1.20.3.Final1.20.3.Final

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

wil**ly-*lytron: possi*l* timin* *tt**ks vi* us* o* uns*** *omp*r*tor. * *l*w w*s *oun* in Wil**ly-*lytron. Wil**ly-*lytron us*s `j*v*.util.*rr*ys.*qu*ls` in s*v*r*l pl***s, w*i** is uns*** *n* vuln*r**l* to timin* *tt**ks. To *omp*r* v*lu*s s**ur*ly

Reasoning

No *n*lysis *v*il**l*