Safety vulnerability ID: 60631
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Python 3.6.13, 3.7.10, 3.8.7, 3.9.1 and 3.10.0a3 include a fix for CVE-2022-48566: Observable Timing Discrepancy vulnerability in compare_digest in Lib/hmac.py. The fix includes constant-time-defeating optimizations were possible in the accumulator variable in hmac.compare_digest.
https://bugs.python.org/issue40791
Latest version: 0.9.8
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. See CVE-2022-48566.
MISC:https://bugs.python.org/issue40791: https://bugs.python.org/issue40791
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application