ZeroHour

CVE-2021-33880

CVSS 3.1
5.9 medium
EPSS
2%p82
Published
()
Modified
Description

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

Vendors
websockets projectoracle
Products
websockets, communications cloud native core policy, communications cloud native core security edge protection proxy, communications cloud native core service communication proxy, communications cloud native core unified data repository
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.