Timing Attack Affecting org.graalvm.sdk:graal-sdk package, versions [,20.3.4)[21.0.0,21.3.0)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (64th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGGRAALVMSDK-1766242
  • published21 Oct 2021
  • disclosed19 Oct 2021
  • creditArtem Smotrakov

Introduced: 19 Oct 2021

CVE-2021-35603  (opens in a new tab)
CWE-208  (opens in a new tab)

How to fix?

Upgrade org.graalvm.sdk:graal-sdk to version 20.3.4, 21.3.0 or higher.

Overview

org.graalvm.sdk:graal-sdk is a high-performance JDK distribution designed to accelerate the execution of applications written in Java and other JVM languages along with support for JavaScript, Ruby, Python, and a number of other popular languages.

Affected versions of this package are vulnerable to Timing Attack. It was discovered that the TLS implementation in the JSSE component of OpenJDK used non-constant comparisons when checking various data (such as session identifiers or verification data blocks) during TLS handshakes. A malicious TLS client could possibly use this flaw to recover that data by observing timing differences in processing of various inputs.

CVSS Scores

version 3.1