Skip to content

Possible timing attack in webhook signature verification method #462

Description

@soumitd

Hi Team,

I think below code is susceptible to a timing attack.

return expectedSignature === signature;

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions