CVE-2024-47178
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-47178 is a vulnerability affecting the basic-auth-connect module in Connect's Basic Auth middleware. The issue lies in an unsafe equality comparison used by basic-auth-connect versions below 1.1.0, which can potentially leak timing information. This security weakness has been resolved in the updated version 1.1.0. The vulnerability could be exploited by an attacker to gain insights into system processing times, potentially leading to further attacks. Developers using outdated versions of basic-auth-connect are encouraged to upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.