QID 982212
QID 982212: Python (pip) Security Update for websockets (GHSA-8ch4-58qp-g3mp)
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8ch4-58qp-g3mp for updates pertaining to this vulnerability.
Vendor References
- GHSA-8ch4-58qp-g3mp -
github.com/advisories/GHSA-8ch4-58qp-g3mp
CVEs related to QID 982212
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8ch4-58qp-g3mp | websockets |
|