Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PW-6905: is_valid_hmac and is_valid_hmac_notification are vulnerable to timing attack #168

Closed
MahamdiAmine opened this issue Jul 9, 2022 · 1 comment

Comments

@MahamdiAmine
Copy link

Description
is_valid_hmac and is_valid_hmac_notification are vulnerable to timing attack, you should compare the hash of the HMACs instead.

@michaelpaul michaelpaul changed the title is_valid_hmac and is_valid_hmac_notification are vulnerable to timing attack PW-6905: is_valid_hmac and is_valid_hmac_notification are vulnerable to timing attack Jul 11, 2022
@jillingk
Copy link
Contributor

Hi @MahamdiAmine,

Massive thanks for bringing this to our attention. We fixed the vulnerability and added it in in our new release!

Best, Jilling
Adyen

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants