[//]: # (werk v2)
# Mitigate timing-unsafe comparisons to prevent byte-by-byte brute forcing attack
key | value
---------- | ---
date | 2024-06-25T10:10:15+00:00
version | 2.4.0b1
class | security
edition | cee
component | agents
level | 1
compatible | yes
A theorical brute force attack could be performed due to timing-unsafe secrets
comparison.
This fix changes the way secrets are verified in communication with the agent.
To aid automated scanning we assign a CVSS score of 0.0 (None)
(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).