You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Learn more on MITRE.
Impact
basic-auth-connect <1.1.0 uses a timing-unsafe equality comparison that can leak timing information
Patches
this issue has been fixed in basic-auth-connect 1.1.0
References