BIT-python-2022-48566

Import Source
https://github.com/bitnami/vulndb/tree/main/data/python/BIT-python-2022-48566.json
Aliases
Published
2024-03-06T11:04:14.285Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

An issue was discovered in comparedigest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.comparedigest.

References

Affected packages

Bitnami / python

Package

Name
python

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
3.6.13
Introduced
3.7.0
Fixed
3.7.10
Introduced
3.8.0
Fixed
3.8.7
Introduced
3.9.0
Fixed
3.9.1