-
Notifications
You must be signed in to change notification settings - Fork 222
Closed
Description
I'm opening this to raise the visibility of CVE-2020-17495, as seen in the current released package version v1.2.1 as mentioned in #142, which is now getting flagged in Pyup Safety scans.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17495
https://nvd.nist.gov/vuln/detail/CVE-2020-17495
╞══════════════════════════════════════════════════════════════════════════════╡
│ REPORT │
│ checked 178 packages, using pyup.io's DB │
╞════════════════════════════╤═══════════╤══════════════════════════╤══════════╡
│ package │ installed │ affected │ ID │
╞════════════════════════════╧═══════════╧══════════════════════════╧══════════╡
│ django-celery-results │ 1.2.1 │ <=1.2.1 │ 38678 │
╞══════════════════════════════════════════════════════════════════════════════╡
│ Django-celery-results through 1.2.1 stores task results in the database. │
│ Among the data it stores are the variables passed into the tasks. The │
│ variables may contain sensitive cleartext information that does not belong │
│ unencrypted in the database. See CVE-2020-17495. │
╘══════════════════════════════════════════════════════════════════════════════╛
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels