Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://github.com/answerdev/answer/commit/813ad0b9894673b1bdd489a2e9ab60a44fe990af | patch |
https://huntr.dev/bounties/ac0271eb-660f-4966-8b57-4bc660a9a1a0 | third party advisory exploit |