An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
2023-08-22T19:16:32.087
2024-11-21T07:33:31.147
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | python | < 3.6.13 | Yes |
Application | python | python | < 3.7.10 | Yes |
Application | python | python | < 3.8.7 | Yes |
Application | python | python | < 3.9.1 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | converged_systems_advisor_agent | - | Yes |