CVE-2013-10031

Description

A flaw was found in Plack-Middleware-Session. This vulnerability allows attackers to perform timing attacks on Hash-based Message Authentication Code (HMAC) comparisons.

Statement

This vulnerability is rated Important for Red Hat products that use Plack::Middleware::Session. A timing attack on HMAC comparison could allow an attacker to infer sensitive information, potentially leading to session hijacking. Successful exploitation requires the ability to accurately measure response times, which may be challenging in typical network environments.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Confidentiality,Authorization

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.