GHSA-xm8r-5wh6-f46f

Suggest an improvement
Source
https://github.com/advisories/GHSA-xm8r-5wh6-f46f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-xm8r-5wh6-f46f/GHSA-xm8r-5wh6-f46f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xm8r-5wh6-f46f
Withdrawn
2021-02-24T19:45:15Z
Published
2021-02-24T19:45:15Z
Modified
2024-12-01T05:38:35Z
Summary
Timing attack
Details

While each ID is used for only one authentication attempt, a timing attack is possible to figure out in Autobahn.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-20T14:32:05Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

PyPI / autobahn

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.4

Affected versions

0.*
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.4.3
0.4.10
0.5.0
0.5.1
0.5.2
0.5.5
0.5.8
0.5.9
0.5.14
0.6.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-xm8r-5wh6-f46f/GHSA-xm8r-5wh6-f46f.json"