VDB

CVE-2021-33880

CVE-2021-33880 PUBLISHED

The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able to guess a password via a timing attack.

EPSS 0.31% · 54.6th percentile

Risk Scores

EPSS Score
0.31%
54.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpython-websockets2.6-1, 0, 3.0-1
Ubuntu:24.04:LTSpython-websockets10.4-1, 0
Ubuntu:20.04:LTSpython-websockets7.0-1, 8.1-1, 0
Ubuntu:22.04:LTSpython-websockets9.1-1, 8.1-1, 0
Ubuntu:25.10python-websockets15.0.1-1, 0, 14.1-1build1
Ubuntu:18.04:LTSpython-websockets0, 3.4-1, 3.3-1

Timeline

  • CVE Published
  • Jun 8, 2021 EPSS Score
  • Jun 19, 2021 EPSS Score
  • Aug 9, 2021 EPSS Score
  • Oct 9, 2021 EPSS Score
  • Dec 9, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 7, 2022 EPSS Score
  • Feb 10, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 9, 2022 EPSS Score
  • Aug 10, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›