Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxf9-7h4c-f5jv

Опубликовано: 12 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

Django-Anymail prone to a timing attack

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

Пакеты

Наименование

django-anymail

pip
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 66%
0.00506
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 8 лет назад

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

CVSS3: 9.1
nvd
около 8 лет назад

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

CVSS3: 9.1
debian
около 8 лет назад

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone ...

EPSS

Процентиль: 66%
0.00506
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-200