Observable discrepancy in websockets - CVE-2021-33880

 

Observable discrepancy in websockets - CVE-2021-33880

Published: June 13, 2021


Vulnerability identifier: #VU54078
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-33880
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to observable timing discrepancy on server when HTTP Basic authentication is enabled with basic_auth_protocol_factory(credentials=...). A remote attacker can guess passwords via timing attack.


Affected software

websockets
Arch Linux
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy

How to mitigate CVE-2021-33880

Install updates from vendor's website.

websockets - update to 9.1

External References

Related Security Bulletins