CVE-2024-47178

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 30, 2024
Updated: Nov 15, 2024
CWE ID 208

Summary

CVE-2024-47178 is a vulnerability affecting the basic-auth-connect module in Connect's Basic Auth middleware. The issue lies in an unsafe equality comparison used by basic-auth-connect versions below 1.1.0, which can potentially leak timing information. This security weakness has been resolved in the updated version 1.1.0. The vulnerability could be exploited by an attacker to gain insights into system processing times, potentially leading to further attacks. Developers using outdated versions of basic-auth-connect are encouraged to upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share