High severity7.5NVD Advisory· Published Jan 28, 2020· Updated Jun 16, 2026
CVE-2013-1895
CVE-2013-1895
Description
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
py-bcryptPyPI | < 0.3 | 0.3 |
Affected products
5cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- lists.fedoraproject.org/pipermail/package-announce/2013-April/101382.htmlnvdThird Party AdvisoryTool SignatureWEB
- lists.fedoraproject.org/pipermail/package-announce/2013-April/101387.htmlnvdThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2013/03/26/2nvdMailing ListThird Party AdvisoryWEB
- www.securityfocus.com/bid/58702nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/83039nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-r838-q6jp-58xxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-1895ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/py-bcrypt/PYSEC-2020-249.yamlghsaWEB
News mentions
0No linked articles in our index yet.