CVE-2022-48566

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48566
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48566.json
Aliases
Related
Published
2023-08-22T19:16:32Z
Modified
2024-05-14T12:35:43.285233Z
Summary
[none]
Details

An issue was discovered in comparedigest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.comparedigest.

References

Affected packages

Git / github.com/python/cpython

Affected versions

v3.*

v3.8.0
v3.8.1
v3.8.1rc1
v3.8.2
v3.8.2rc1
v3.8.2rc2
v3.8.3
v3.8.3rc1
v3.8.4
v3.8.4rc1
v3.8.5
v3.8.6
v3.8.6rc1
v3.8.7rc1