CVE-2021-33880

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:websockets_project:websockets:*:*:*:*:*:python:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.14.0:*:*:*:*:*:*:*

History

12 May 2022, 14:07

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
First Time Oracle communications Cloud Native Core Policy
References (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory
References (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Patch, Third Party Advisory

20 Apr 2022, 00:16

Type Values Removed Values Added
References
  • (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html -

09 Feb 2022, 14:55

Type Values Removed Values Added
CPE cpe:2.3:a:websockets_project:websockets:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:websockets_project:websockets:*:*:*:*:*:python:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.14.0:*:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-203
First Time Oracle communications Cloud Native Core Security Edge Protection Proxy
Oracle
Oracle communications Cloud Native Core Service Communication Proxy
Oracle communications Cloud Native Core Unified Data Repository
References (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Third Party Advisory

07 Feb 2022, 16:16

Type Values Removed Values Added
References
  • (MISC) https://www.oracle.com/security-alerts/cpujan2022.html -

16 Jun 2021, 16:07

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 2.6
v3 : 5.9
References (MISC) https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0 - (MISC) https://github.com/aaugustin/websockets/commit/547a26b685d08cac0aa64e5e65f7867ac0ea9bc0 - Patch, Third Party Advisory
CWE NVD-CWE-Other
CPE cpe:2.3:a:websockets_project:websockets:*:*:*:*:*:*:*:*

06 Jun 2021, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-06 15:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-33880

Mitre link : CVE-2021-33880

CVE.ORG link : CVE-2021-33880


JSON object : View

Products Affected

oracle

  • communications_cloud_native_core_security_edge_protection_proxy
  • communications_cloud_native_core_policy
  • communications_cloud_native_core_unified_data_repository
  • communications_cloud_native_core_service_communication_proxy

websockets_project

  • websockets
CWE
CWE-203

Observable Discrepancy