VDB
Sign up
—

PYSEC-2017-102

Quick fix

PYSEC-2017-102 — radicale: upgrade to the fixed version with the command below.

pip install --upgrade 'radicale>=190b1dd795f0c552a4992445a231da760211183b'

Details

Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/radicale
Introduced in: 0Fixed in: 190b1dd795f0c552a4992445a231da760211183b
Fixpip install --upgrade 'radicale>=190b1dd795f0c552a4992445a231da760211183b'

References