Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-w277-wpqf-rcfv: Svix vulnerable to improper comparison of different-length signatures

The Webhook::verify function incorrectly compared signatures of different lengths - the two signatures would only be compared up to the length of the shorter signature. This allowed an attacker to pass in v1, as the signature, which would always pass verification.

ghsa
#web#git

Svix vulnerable to improper comparison of different-length signatures

Moderate severity GitHub Reviewed Published Feb 6, 2024 to the GitHub Advisory Database • Updated Feb 6, 2024

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation