Description
Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have an observable timing discrepancy vulnerability. Successful exploitation could lead to signature verification bypass.
Remediation
References
Related Vulnerabilities
WordPress Plugin ZWM Zeumic Work Management Multiple Unspecified Vulnerabilities (1.0.11)
WordPress Plugin Affiliates Manager Cross-Site Scripting (2.8.9)
Java Unspesificed Vulnerability (CVE-2019-2422)
MySQL CVE-2016-0642 Vulnerability (CVE-2016-0642)
WordPress Plugin WooCommerce Checkout Manager Multiple Unspecified Vulnerabilities (3.6.9)