CVE-2016-15015

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-15015
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-15015.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-15015
Aliases
Published
2023-01-08T18:15:10Z
Modified
2024-05-17T07:49:47.884162Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 3e7d29dc0ca6c054a6d6e211f32dae89078594c1. It is recommended to upgrade the affected component. VDB-217650 is the identifier assigned to this vulnerability.

References

Affected packages

Git / github.com/viafintech/barzahlen-php

Affected ranges

Type
GIT
Repo
https://github.com/viafintech/barzahlen-php
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.7
v1.1.8

v2.*

v2.0.0