提交 559566b1 编写于 作者: D Daniel Beck

[FIX SECURITY-245] Compare crumbs in constant time

上级 536c01bf
......@@ -95,7 +95,7 @@ public class DefaultCrumbIssuer extends CrumbIssuer {
if (request instanceof HttpServletRequest) {
String newCrumb = issueCrumb(request, salt);
if ((newCrumb != null) && (crumb != null)) {
return newCrumb.equals(crumb);
return MessageDigest.isEqual(newCrumb.getBytes(), crumb.getBytes());
}
}
return false;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册