CVE detail
CVE-2015-20110 — CVE-2015-20110
Published 2023-10-31 · Modified 2026-06-17 · Vendor jhipster · Product jhipster · Source nvd
HIGH
severity
CVSS-derived band
0.0059
EPSS probability
exploitation probability, 30d
45.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References