Skip to content

Fix possible timing leak in validate_password - #1535

Merged
prandla merged 1 commit into
cms-dev:mainfrom
prandla:validate-passwd-timing
Aug 27, 2025
Merged

Fix possible timing leak in validate_password#1535
prandla merged 1 commit into
cms-dev:mainfrom
prandla:validate-passwd-timing

Conversation

@prandla

@prandla prandla commented Aug 27, 2025

Copy link
Copy Markdown
Member

Using == on password hashes (or passwords themselves) is vulnerable to a timing attack. I very much doubt that this is attackable in practice, but doing it correctly is so easy that there's no reason not to.

@prandla
prandla merged commit 6ced7a5 into cms-dev:main Aug 27, 2025
4 checks passed
@prandla
prandla deleted the validate-passwd-timing branch August 27, 2025 22:14
ronryv added a commit to ioi-isr/cms that referenced this pull request Nov 1, 2025
* CWS: Mark ajax request endpoints as @api_login_required (cms-dev#1522)

This prevents cases where they would redirect to the login screen
unexpectedly. Also improved handling of errors in the submission details
popup.

* AWS: don't refresh the page when contest phase changes (cms-dev#1510)

* make AWS more resilient towards missing ScoreTypes and Languages (cms-dev#1460)

* Translated using Weblate (Estonian)

Currently translated at 100.0% (311 of 311 strings)

Translation: CMS/main
Translate-URL: https://hosted.weblate.org/projects/cms/main/et/

* Translated using Weblate (French)

Currently translated at 100.0% (311 of 311 strings)

Translation: CMS/main
Translate-URL: https://hosted.weblate.org/projects/cms/main/fr/

* Translated using Weblate (Arabic)

Currently translated at 54.9% (171 of 311 strings)

Translation: CMS/main
Translate-URL: https://hosted.weblate.org/projects/cms/main/ar/

* Translated using Weblate (Chinese (Traditional Han script))

Currently translated at 67.5% (210 of 311 strings)

Translation: CMS/main
Translate-URL: https://hosted.weblate.org/projects/cms/main/zh_Hant/

* Translated using Weblate (Italian)

Currently translated at 100.0% (311 of 311 strings)

Translation: CMS/main
Translate-URL: https://hosted.weblate.org/projects/cms/main/it/

* Initialize Hebrew translation

* mention weblate more explicitly in README (cms-dev#1531)

this was requested by the Weblate support team.

* Remove some unused files (cms-dev#1533)

We don't use codacy any more (at least it doesn't seem so?) and we use
weblate instead of onesky now.

* Fix possible timing leak in validate_password (cms-dev#1535)

* Make the helper scripts in docker/ a bit more robust

When the git repo is in a detached HEAD state, GIT_BRANCH_NAME became
"HEAD", which docker does not like as a project name. So I lowercased it
and added a cms- in front for good measure.

* Make functional test suite not depend on git

* Bump gevent from 25.5.1 to 25.8.1 (cms-dev#1538)

Bumps [gevent](https://github.com/gevent/gevent) from 25.5.1 to 25.8.1.
- [Release notes](https://github.com/gevent/gevent/releases)
- [Changelog](https://github.com/gevent/gevent/blob/master/docs/changelog_pre.rst)
- [Commits](gevent/gevent@25.5.1...25.8.1)

---
updated-dependencies:
- dependency-name: gevent
  dependency-version: 25.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* fix schema_diff_test on new debian (cms-dev#1551)

* Bump zope-event from 5.1 to 6.0 (cms-dev#1555)

Bumps [zope-event](https://github.com/zopefoundation/zope.event) from 5.1 to 6.0.
- [Changelog](https://github.com/zopefoundation/zope.event/blob/master/CHANGES.rst)
- [Commits](zopefoundation/zope.event@5.1...6.0)

---
updated-dependencies:
- dependency-name: zope-event
  dependency-version: '6.0'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump zope-interface from 7.2 to 8.0 (cms-dev#1554)

Bumps [zope-interface](https://github.com/zopefoundation/zope.interface) from 7.2 to 8.0.
- [Changelog](https://github.com/zopefoundation/zope.interface/blob/master/CHANGES.rst)
- [Commits](zopefoundation/zope.interface@7.2...8.0)

---
updated-dependencies:
- dependency-name: zope-interface
  dependency-version: '8.0'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump version to 1.6.dev0 (cms-dev#1532)

* Add rws public config and configurable id column

* Avoid reading GEN if score parameters are already found in task.yaml

* Fixes

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: p. randla <prandla@r9.pm>
Co-authored-by: Pasit Sangprachathanarak <ouipingpasit@gmail.com>
Co-authored-by: Muaath Alqarni <translate@muaath.dev>
Co-authored-by: LittleCube <froakie20161113@gmail.com>
Co-authored-by: William Di Luigi <williamdiluigi@gmail.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Elia Soldati <eliasol2005@gmail.com>
Co-authored-by: Francesco Vercellesi <francesco@vercellesi.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants