Skip to content

Username timing attack

Low
bartvanb published GHSA-45gq-q4xh-cp53 Jan 30, 2024

Package

pip vantage6-server (pip)

Affected versions

< 4.1.3

Patched versions

4.2.0+

Description

Impact

It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks

Patches

No

Workarounds

No

Severity

Low

CVE ID

CVE-2024-21671

Weaknesses