GHSA-8ch4-58qp-g3mp
HIGHCVE-2021-33880The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basicauthprotocolfactory(credentials=...). An attacker may be able to guess a password via a timing attack.
- Affected
- < 9.1
- Fixed in
- 9.1
- Weakness
- CWE-203
- Published
- 2021-06-11
- Source
- github