MEDIUM5.3
GHSA-f3q4-ggfp-jv34
Adyen APIs Library for Python timing attack vulnerability
Quick fix
GHSA-f3q4-ggfp-jv34 — adyen: upgrade to the fixed version with the command below.
pip install --upgrade 'adyen>=7.1.0'Details
Adyen has utility methods for validating notification HMAC signatures. The `is_valid_hmac` and `is_valid_hmac_notification` methods are vulnerable to a timing attack, you should compare the hash of the HMACs instead.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Adyen/adyen-python-api-library/issues/168[WEB]
- https://github.com/Adyen/adyen-python-api-library/pull/170[WEB]
- https://github.com/Adyen/adyen-python-api-library/commit/3292133dbc00ffc4cccfb92de672a76eaa587ca5[WEB]
- https://github.com/Adyen/adyen-python-api-library[PACKAGE]
- https://github.com/pypa/advisory-database/tree/main/vulns/adyen/PYSEC-2023-1.yaml[WEB]