CVE-2012-4571

Python Keyring 0.9.1 - Info Disclosure

Title source: llm

Description

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Scores

EPSS 0.0006
EPSS Percentile 20.1%

Classification

CWE
CWE-310
Status draft

Affected Products (2)

python/keyring
pypi/keyring < 0.9.2PyPI

Timeline

Published Nov 30, 2012
Tracked Since Feb 18, 2026