VDB
Sign up
HIGH7.5

PYSEC-2024-290

Details

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/openslides
Introduced in: 0

No fixed version published yet for openslides (pip). Pin to a known-safe version or switch to an alternative.

References