Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vhw-q7vh-7xv2

Опубликовано: 01 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

Summary

The /ready endpoint in openssl_encrypt_server/server.py at lines 159-175 catches database errors and returns the full exception string in the response.

Affected Code

except Exception as e: return {"status": "not_ready", "reason": str(e)}

Impact

Database exception messages can leak:

  • Database hostnames and IP addresses
  • Connection parameters and port numbers
  • Driver version information
  • Potentially database credentials if included in connection string errors

This information is available to unauthenticated callers.

Recommended Fix

  • Return a generic error message: {"status": "not_ready", "reason": "database unavailable"}
  • Log the full exception server-side for debugging

Fix

Fixed in commit 7aa8787 on branch releases/1.4.x — replaced str(e) with generic "database check failed" message; full exception logged server-side at WARNING level.

Пакеты

Наименование

openssl-encrypt

pip
Затронутые версииВерсия исправления

< 1.4.0

1.4.0

6.6 Medium

CVSS4

Дефекты

CWE-201

6.6 Medium

CVSS4

Дефекты

CWE-201