7.4
CVSSv3

CVE-2018-1000089

Published: 13/03/2018 Updated: 11/04/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Anymail django-anymail version version 0.2 up to and including 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

Vulnerable Product Search on Vulmon Subscribe to Product

django-anymail project django-anymail

Vendor Advisories

Debian Bug report logs - #890097 django-anymail: CVE-2018-1000089: WEBHOOK_AUTHORIZATION secret disclosure when debug enabled Package: src:django-anymail; Maintainer for src:django-anymail is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Scott Kitterman <debian@kittermancom> D ...