{"id":"GHSA-hjhr-r3gq-qvp6","summary":"Timing Attack in csrf-lite","details":"Affected versions of `csrf-lite` are vulnerable to timing attacks as a result of testing CSRF tokens via a fail-early comparison instead of a constant-time comparison. \n\nTiming attacks remove the exponential increase in entropy gained from increased secret length, by providing per-character feedback on the correctness of a guess via miniscule timing differences.\n\nUnder favorable network conditions, an attacker can exploit this to guess the secret in no more than (16*18)288 guesses, instead of the 16^18 guesses required were the timing attack not present. \n\n\n## Recommendation\n\nUpdate to version 0.1.2 or later.","aliases":["CVE-2016-10535"],"modified":"2023-11-08T03:58:11.147657Z","published":"2019-02-18T23:39:44Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:40:36Z","nvd_published_at":null,"cwe_ids":["CWE-208"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10535"},{"type":"WEB","url":"https://github.com/isaacs/csrf-lite/pull/1"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hjhr-r3gq-qvp6"},{"type":"WEB","url":"https://www.npmjs.com/advisories/94"}],"affected":[{"package":{"name":"csrf-lite","ecosystem":"npm","purl":"pkg:npm/csrf-lite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-hjhr-r3gq-qvp6/GHSA-hjhr-r3gq-qvp6.json"}}],"schema_version":"1.9.0"}