← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-43298

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that an unauthenticated network attacker can brute-force the HTTP basic password, byte-by-byte, by recording the webserver's response time until the unauthorized (401) response.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
embedthis goahead unspecified < 5.1.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.256%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityJFrog · Vendor · Israel
Reserved2021-11-03T00:00:00
Published2022-01-25T19:11:17
Last Updated2024-08-04T03:55:28

LINK COPIED TO CLIPBOARD