HIGH7.5
PYSEC-2024-290
Details
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openslides
Introduced in:
0No fixed version published yet for openslides (pip). Pin to a known-safe version or switch to an alternative.