Skip to content

Go : Add query to detect timing attacks #757

@ghost

Description

Query PR

github/codeql#13119

Language

GoLang

CVE(s) ID list

CVE-2022-24912
I have a couple more I have found. I will add them later.

CWE

CWE-203

Report

This query detects instances where a non-contact comparision is used to compare two sensitive strings.

I have found multiple CVE's through this query. I don't know if those will qualify for Bug Slayer since some of them look like medium severity issues to me. I will open one if I can manage to meet the program requirements.

Are you planning to discuss this vulnerability submission publicly? (Blog Post, social networks, etc).

  • Yes
  • No

Blog post link

tba

Metadata

Metadata

Assignees

Labels

All For OneSubmissions to the All for One, One for All bounty

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions