@perfood/couch-auth
cpe:2.3:a:perfood:couchauth:*:*:*:*:node.js:*:*
- <= 0.26.0
A timing side-channel vulnerability has been identified in the authentication logic of @perfood/couch-auth version 0.26.0. This vulnerability allows remote attackers to access sensitive information by exploiting the timing discrepancy in the authentication process, potentially leading to the guessing of sensitive tokens.
Exploitation of this vulnerability could allow attackers to perform side-channel attacks that guess sensitive tokens, which could be used to compromise user accounts or access restricted resources.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.