Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fixed timing attack vulnerability in TokenProvider #2096

Merged
merged 2 commits into from Oct 16, 2015
Merged

fixed timing attack vulnerability in TokenProvider #2096

merged 2 commits into from Oct 16, 2015

Conversation

ghost
Copy link

@ghost ghost commented Oct 6, 2015

Fixed #2095 using a fixed time string comparison

@jdubois
Copy link
Member

jdubois commented Oct 16, 2015

I'm merging this because migrating to JWT will take some time

jdubois added a commit that referenced this pull request Oct 16, 2015
fixed timing attack vulnerability in TokenProvider
@jdubois jdubois merged commit 7c49ab3 into jhipster:master Oct 16, 2015
@jdubois jdubois modified the milestone: 2.23.0 Oct 21, 2015
naymesh added a commit to IntegratedBreedingPlatform/BMSAPI that referenced this pull request Nov 17, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security: TokenProvider vulnerable to timing attacks
1 participant