CVE-2024-21671
LOW3.7EPSS 0.22%vantage6 vulnerable to username timing attack
Published: 1/30/2024Modified: 2/4/2026
Description
### Impact It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks ### Workarounds No
Affected packages (2)
- PyPI/vantage6from 0, < 389f416c445da4f2438c72f34c3b1084485c4e30 | from 0, < 4.2.0
- PyPI/vantage6-serverfrom 0, < 4.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-21671
- PATCHhttps://github.com/vantage6/vantage6
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/vantage6/PYSEC-2024-31.yaml
- WEBhttps://github.com/vantage6/vantage6/commit/389f416c445da4f2438c72f34c3b1084485c4e30
- WEBhttps://github.com/vantage6/vantage6/security/advisories/GHSA-45gq-q4xh-cp53