First published: Sun Jun 06 2021(Updated: )
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Websockets Project Websockets Python | <9.1 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Cloud Native Core Security Edge Protection Proxy | =1.5.0 | |
Oracle Communications Cloud Native Core Service Communication Proxy | =1.14.0 | |
Oracle Communications Cloud Native Core Unified Data Repository | =1.14.0 | |
pip/websockets | <9.1 | 9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-33880 is medium.
CVE-2021-33880 affects the aaugustin websockets library version up to 9.1.
The vulnerability in CVE-2021-33880 is an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory.
An attacker can exploit CVE-2021-33880 by guessing a password via a timing attack.
Yes, fixes are available for CVE-2021-33880. Please refer to the references for more information.