4.0.6
9 years ago
2 months ago
Known vulnerabilities in the patroni package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
patroni is a PostgreSQL High-Available orchestrator and CLI. Affected versions of this package are vulnerable to Timing Attack via auth key comparison, as 'hmac.compare_digest()' is used instead of '==' for performing the REST API authentication. How to fix Timing Attack? Upgrade | [0,2.0.2) |