Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvx8-v524-8579

Опубликовано: 04 июн. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

django-celery-results Stores Sensitive Information In Cleartext

django-celery-results prior to 2.4.0 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

In version 2.4.0 this is no longer the default behaviour but can be re-enabled with the result_extended flag in which case care should be taken to ensure any sensitive variables are scrubbed - see here for an example.

Пакеты

Наименование

django-celery-results

pip
Затронутые версииВерсия исправления

< 2.4.0

2.4.0

EPSS

Процентиль: 35%
0.00148
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

CVSS3: 7.5
nvd
больше 5 лет назад

django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

CVSS3: 7.5
debian
больше 5 лет назад

django-celery-results through 1.2.1 stores task results in the databas ...

EPSS

Процентиль: 35%
0.00148
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-312