Safety vulnerability ID: 25915
The information on this page was manually curated by our Cybersecurity Intelligence Team.
otpauth before 1.0.1 is vulnerable to timing attacks. https://github.com/authlib/otpauth…
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 2.1.1
Implements one time password of HOTP/TOTP
~~~~~~~~~~~~~ Released on May 26, 2015 Use ``compare_digest`` to avoid timing attack.
[This text has been limited. Please create a free account to view the full text.]
Create a free account to access detailed CVSS severity scores and full vulnerability advisories
Create free account