python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Python-jose |
Python-jose_project |
* |
1.3.1 (including) |
References