Skip to main content

Observable Discrepancy

CVE-2021-4286

Severity High
Score 7.5/10

Summary

A vulnerability, which was classified as problematic, has been found in srp package versions through 1.0.16. This issue affects the function "calculate_x" of the file "srp/_ctsrp.py". The manipulation leads to information exposure through discrepancy. Upgrading to version 1.0.17 is able to address this issue. The name of the patch is "dba52642f5e95d3da7af1780561213ee6053195f". It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216875.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-203 - Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Advisory Timeline

  • Published