Логотип exploitDog
bind:CVE-2018-1000089
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1000089

Количество 4

Количество 4

ubuntu логотип

CVE-2018-1000089

почти 8 лет назад

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2018-1000089

почти 8 лет назад

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2018-1000089

почти 8 лет назад

Anymail django-anymail version version 0.2 through 1.3 contains a CWE- ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-qh9x-mc42-vg4g

больше 3 лет назад

django-anymail Includes Sensitive Information in Log Files

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-1000089

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

CVSS3: 7.4
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-1000089

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

CVSS3: 7.4
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-1000089

Anymail django-anymail version version 0.2 through 1.3 contains a CWE- ...

CVSS3: 7.4
0%
Низкий
почти 8 лет назад
github логотип
GHSA-qh9x-mc42-vg4g

django-anymail Includes Sensitive Information in Log Files

CVSS3: 7.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу