Anonymous committed b7962f4

Fixed #15627 -- Use constant time comparison for password checks. Thanks to hvdklauw for the report and patch.

Comments (0)

Files changed (1)


 from django.utils.encoding import smart_str
 from django.utils.hashcompat import md5_constructor, sha_constructor
 from django.utils.translation import ugettext_lazy as _
+from django.utils.crypto import constant_time_compare
 UNUSABLE_PASSWORD = '!' # This will never be a valid hash
     encryption formats behind the scenes.
     algo, salt, hsh = enc_password.split('$')
-    return hsh == get_hexdigest(algo, salt, raw_password)
+    return constant_time_compare(hsh, get_hexdigest(algo, salt, raw_password))
 def update_last_login(sender, user, **kwargs):