Timing Attack Vulnerability in RELATE Web-Based Courseware Package

⚠️ CVE-Referenzen: CVE-2026-41588
Inducer - Relate - CRITICAL - CVE-2026-41588. The RELATE web-based courseware package contains a timing attack vulnerability in the check_sign_in_key function located in course/auth.py. This security flaw could allow attackers to infer sensitive information through carefully timed requests, jeopardizing the integrity of user authentication processes. The vulnerability was addressed in commit 2f68e16, which provides a patch to mitigate this risk. Users of the affected RELATE version are encouraged to update to the latest version to ensure their systems are protected.
Quelle: securityvulnerability.io