Описание
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
Ссылки
- Issue TrackingPatchThird Party Advisory
- Patch
- Patch
- Release Notes
- Release Notes
- Third Party Advisory
- Issue TrackingPatchThird Party Advisory
- Patch
- Patch
- Release Notes
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.1 (исключая)
cpe:2.3:a:django-anymail_project:django-anymail:*:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00506
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 9.1
ubuntu
около 8 лет назад
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
CVSS3: 9.1
debian
около 8 лет назад
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone ...
EPSS
Процентиль: 66%
0.00506
Низкий
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-200