CWE-208
185 CVEs • Abstraction: Base
Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
CVEs (185)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Wagtail before versions 2.7.3 and 2.8.2, a potential timing attack exists on pages or documents that have been protected with a shared password through Wagtail's "Privacy" controls. This password check is performed th...Show more |
3Fedoraproject OpensuseRack3Fedora LeapRackJun 17, 2026 Dec 18, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing att...Show more |
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database. |
5Fedoraproject FreebsdOpensuse+2 more8Backports Sle FedoraFreebsd+5 moreJun 17, 2026 Apr 17, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information f...Show more |
1Csrf Lite Project 1Csrf Lite Nov 21, 2024 May 31, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail first string comparison, instead of a time constant string comparison This enables an attacker to g...Show more |