Description
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0467 | The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack. |
Github GHSA |
GHSA-8ch4-58qp-g3mp | Observable Timing Discrepancy in aaugustin websockets library |
References
History
No history.
Subscriptions
Oracle
Subscribe
Communications Cloud Native Core Policy
Subscribe
Communications Cloud Native Core Security Edge Protection Proxy
Subscribe
Communications Cloud Native Core Service Communication Proxy
Subscribe
Communications Cloud Native Core Unified Data Repository
Subscribe
Websockets Project
Subscribe
Websockets
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T00:05:51.647Z
Reserved: 2021-06-06T00:00:00.000Z
Link: CVE-2021-33880
No data.
Status : Modified
Published: 2021-06-06T15:15:07.407
Modified: 2024-11-21T06:09:42.373
Link: CVE-2021-33880
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA