Headline
GHSA-f3q4-ggfp-jv34: Adyen APIs Library for Python timing attack vulnerability
Adyen has utility methods for validating notification HMAC signatures. The is_valid_hmac
and is_valid_hmac_notification
methods are vulnerable to a timing attack, you should compare the hash of the HMACs instead.
Adyen APIs Library for Python timing attack vulnerability
Moderate severity GitHub Reviewed Published Aug 30, 2024 to the GitHub Advisory Database • Updated Aug 30, 2024