{"id":"PYSEC-2017-102","details":"Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.","aliases":["CVE-2017-8342","GHSA-rpv4-63g3-9x23"],"modified":"2026-06-10T17:02:34.980559340Z","published":"2017-04-30T15:59:00Z","references":[{"type":"FIX","url":"https://github.com/Kozea/Radicale/commit/190b1dd795f0c552a4992445a231da760211183b"},{"type":"FIX","url":"https://github.com/Kozea/Radicale/commit/059ba8dec1f22ccbeab837e288b3833a099cee2d"},{"type":"WEB","url":"https://github.com/Kozea/Radicale/blob/1.1.2/NEWS.rst"},{"type":"WEB","url":"https://bugs.debian.org/861514"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2020/04/msg00019.html"},{"type":"PACKAGE","url":"https://pypi.org/project/radicale"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8342"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-rpv4-63g3-9x23"}],"affected":[{"package":{"name":"radicale","ecosystem":"PyPI","purl":"pkg:pypi/radicale"},"ranges":[{"type":"GIT","repo":"https://github.com/Kozea/Radicale","events":[{"introduced":"0"},{"fixed":"190b1dd795f0c552a4992445a231da760211183b"},{"fixed":"059ba8dec1f22ccbeab837e288b3833a099cee2d"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.2"}]}],"versions":["0.10","0.2","0.3","0.4","0.5","0.6","0.6.1","0.6.2","0.6.3","0.6.4","0.7","0.7.1","0.8","0.9","0.9b1","0.9b2","1.0","1.0.1","1.1","1.1.1","2.0.0rc1","archive/1.0.x","0.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/radicale/PYSEC-2017-102.yaml"}}],"schema_version":"1.7.5"}