VulnerabilityModified
CVE-2021-33880
An attacker may be able to guess a password via a timing attack.
MEDIUM 5.9EPSS 2.27%
Does this matter?
Lower severity and a low EPSS score (2.27%). Track it; it rarely justifies an emergency change on its own.
Description
The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.27% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- websockets project/websockets · oracle/communications cloud native core policy · oracle/communications cloud native core security edge protection proxy · oracle/communications cloud native core service communication proxy · oracle/communications cloud native core unified data repository
- Source
- cve@mitre.org
References
- https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.