CVE-2018-6596

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
03/02/2018
Last modified:
02/03/2018

Description

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:django-anymail_project:django-anymail:*:*:*:*:*:*:*:* 1.2.1 (excluding)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*