totp-rs
RFC-compliant TOTP implementation with ease of use as a goal and additionnal QoL features.
Activity
- Latest release
- 1mo ago
- Total releases
- 51
- Cadence
- ~16 days
- Last 12 months
- 3
Reach
- Downloads
- 8.8M
- Stars
- 271
Details
- License
- MIT
- First release
- Apr 13, 2020
| Version | Released | |
|---|---|---|
6.0.0
major
|
6.0.0
major
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
5.7.2
unknown
| ||
5.7.1
unknown
| ||
5.7.0
unknown
| ||
5.6.0
unknown
| ||
5.5.1
unknown
| ||
5.5.0
unknown
| ||
5.4.0
unknown
| ||
5.3.0
unknown
| ||
5.2.0
unknown
| ||
5.1.0
unknown
| ||
5.0.2
unknown
| ||
5.0.1
unknown
| ||
5.0.0
unknown
|
5.0.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.2.0
unknown
|
4.2.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.1.0
unknown
|
4.1.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.0.0
unknown
|
4.0.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
3.1.0
unknown
|
3.1.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.1
unknown
|
3.0.1
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.0.0
unknown
yanked
|
3.0.0
unknown
yanked
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
2.0.1
unknown
|
2.0.1
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
2.0.0
unknown
|
2.0.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.4.0
unknown
|
1.4.0
unknown
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
1.3.0
unknown
|
1.3.0
unknown
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.1
unknown
|
1.2.1
unknown
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.2.0
unknown
|
1.2.0
unknown
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.1.0
unknown
|
1.1.0
unknown
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.0.0
unknown
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.4
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.3
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.7.2
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.7.2
unknown
yanked
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.7.1
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.7.1
unknown
yanked
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.6.5
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.6.5
unknown
yanked
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.6.4
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.3
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.2
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.1
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.6.0
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.5.0
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.1
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.4.0
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.2
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.1
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.3.0
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.6
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.5
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.4
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.3
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.2
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
0.2.1
unknown
yanked
1 CVE
CVE-2022-29185
GHSA-8vxv-2g8p-2249
RUSTSEC-2022-0018
May 24, 2022
Observable Timing Discrepancy in totp-rs
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactToken comparison was not constant time, and could theorically be used to guess value of an TOTP token, and thus reuse it in the same time window. The attacker would have to know the password beforehand nonetheless. PatchesLibrary now used constant-time comparison. WorkaroundsNo. For more informationIf you have any questions or comments about this advisory:
Fixed in
1.1.0
References
Updated Nov 08, 2023 · Source: OSV.dev |