{"id":"GHSA-xm8r-5wh6-f46f","summary":"Timing attack","details":"While each ID is used for only one authentication attempt, a timing attack is possible to figure out in Autobahn.","modified":"2024-12-01T05:38:35.586931Z","published":"2021-02-24T19:45:15Z","withdrawn":"2021-02-24T19:45:15Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2019-06-20T14:32:05Z"},"references":[{"type":"WEB","url":"https://github.com/crossbario/autobahn-python/issues/157"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/WS-2013-0019"}],"affected":[{"package":{"name":"autobahn","ecosystem":"PyPI","purl":"pkg:pypi/autobahn"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.6.4"}]}],"versions":["0.3.1","0.3.2","0.4.0","0.4.1","0.4.10","0.4.2","0.4.3","0.5.0","0.5.1","0.5.14","0.5.2","0.5.5","0.5.8","0.5.9","0.6.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-xm8r-5wh6-f46f/GHSA-xm8r-5wh6-f46f.json"}}],"schema_version":"1.9.0"}