The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.14.0"
},
{
"last_affected": "1.14.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_cloud_native_core_policy"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.5.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.5.0"
},
{
"last_affected": "1.5.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_cloud_native_core_security_edge_protection_proxy"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.14.0"
},
{
"last_affected": "1.14.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_cloud_native_core_service_communication_proxy"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.14.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.14.0"
},
{
"last_affected": "1.14.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:communications_cloud_native_core_unified_data_repository"
}
]
}{
"cpe": "cpe:2.3:a:websockets_project:websockets:*:*:*:*:*:python:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "9.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}