CVE-2022-48566
published 2023-08-22CVE-2022-48566: An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator…
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.15%
63.2th percentile
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pypy3 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| debian | python2.7 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2 (bookworm) | pypy3 7.3.5+dfsg-2 (bookworm) |
| python | python | < 3.6.13 | 3.6.13 |
| python | python | >= 3.7.0 < 3.7.10 | 3.7.10 |
| python | python | >= 3.8.0 < 3.8.7 | 3.8.7 |
| python | python | >= 3.9.0 < 3.9.1 | 3.9.1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python2.7 vulnerabilities
osv·2025-01-06·CVSS 7.5
CVE-2022-48560 [HIGH] python2.7 vulnerabilities
python2.7 vulnerabilities
It was discovered that Python incorrectly handled certain scripts.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2022-48560)
It was discovered that Python did not properly handle XML entity
declarations in plist files. An attacker could possibly use this
vulnerability to perform an XML External Entity (XXE) injection,
resulting in a denial of service or information disclosure.
(CVE-2022-48565)
It was discovered that Python did not properly provide constant-time
processing for a crypto operation. An attacker could possibly use this
issue to perform a timing attack and recover sensitive information.
(CVE-2022-48566)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-cgfh-jp5w-8cmx: An issue was discovered in compare_digest in Lib/hmac
ghsa_unreviewed·2023-08-22
CVE-2022-48566 [MEDIUM] CWE-362 GHSA-cgfh-jp5w-8cmx: An issue was discovered in compare_digest in Lib/hmac
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
OSV
CVE-2022-48566: An issue was discovered in compare_digest in Lib/hmac
osv·2023-08-22·CVSS 5.9
CVE-2022-48566 [MEDIUM] CVE-2022-48566: An issue was discovered in compare_digest in Lib/hmac
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-01-06·CVSS 7.5
CVE-2022-48560 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python 2.7.
It was discovered that Python incorrectly handled certain scripts.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2022-48560)
It was discovered that Python did not properly handle XML entity
declarations in plist files. An attacker could possibly use this
vulnerability to perform an XML External Entity (XXE) injection,
resulting in a denial of service or information disclosure.
(CVE-2022-48565)
It was discovered that Python did not properly provide constant-time
processing for a crypto operation. An attacker could possibly use this
issue to perform a timing attack and recover sensitive information.
(CVE-2022-48566)
It was discovered that Python incorrect
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Ubuntu
Python vulnerability
vendor_ubuntu·2023-09-27
CVE-2022-48566 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to expose sensitive information.
It was discovered that Python did not properly provide constant-time
processing for a crypto operation. An attacker could possibly use this
issue to perform a timing attack and recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p
vendor_redhat·2023-08-22·CVSS 5.9
CVE-2022-48566 [MEDIUM] CWE-362 python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p
python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
A constant-time-defeating optimization issue was found in python. This issue occurs when sending a specially crafted request, which could allow an attacker to obtain sensitive information.
Statement: This flaw is classified as Moderate as in contrast to an Important rating, the exploitation of this vulnerability is difficult to achieve and the outcome of the impact is breach of confidentiality.
Versions of `python36:3.6/python36` as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they
Debian
CVE-2022-48566: pypy3 - An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1...
vendor_debian·2022·CVSS 5.9
CVE-2022-48566 [MEDIUM] CVE-2022-48566: pypy3 - An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1...
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Scope: local
bookworm: resolved (fixed in 7.3.5+dfsg-2)
bullseye: resolved (fixed in 7.3.5+dfsg-2)
forky: resolved (fixed in 7.3.5+dfsg-2)
sid: resolved (fixed in 7.3.5+dfsg-2)
trixie: resolved (fixed in 7.3.5+dfsg-2)
No detection rules found.
No public exploits indexed.
https://bugs.python.org/issue40791https://lists.debian.org/debian-lts-announce/2023/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20231006-0013/https://bugs.python.org/issue40791https://lists.debian.org/debian-lts-announce/2023/09/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20231006-0013/
2023-08-22
Published