GHSA-8ch4-58qp-g3mp
Dashboard / Vulnerabilities / GHSA-8ch4-58qp-g3mp
GHSA-8ch4-58qp-g3mp
Summary: Observable Timing Discrepancy in aaugustin websockets library
Details: The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-33880, https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0, https://github.com/aaugustin/websockets, https://github.com/pypa/advisory-database/tree/main/vulns/websockets/PYSEC-2021-95.yaml, https://www.oracle.com/security-alerts/cpuapr2022.html, https://www.oracle.com/security-alerts/cpujan2022.html
Affected packages
Package
Name: websockets
Purl: pkg:pypi/websockets
Affected ranges
Type: ECOSYSTEM
Events:
