5.9
CVSSv3

CVE-2021-33880

Published: 06/06/2021 Updated: 12/05/2022
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

The aaugustin websockets library prior to 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

websockets project websockets

oracle communications cloud native core policy 1.14.0

oracle communications cloud native core unified data repository 1.14.0

oracle communications cloud native core service communication proxy 1.14.0

oracle communications cloud native core security edge protection proxy 1.5.0

Vendor Advisories

Debian Bug report logs - #989561 python-websockets: CVE-2021-33880 Package: src:python-websockets; Maintainer for src:python-websockets is Piotr Ożarowski <piotr@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 7 Jun 2021 15:36:01 UTC Severity: important Tags: security, upstream Found ...
The aaugustin websockets library before 91 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=) An attacker may be able to guess a password via a timing attack ...