5
CVSSv2

CVE-2020-17495

Published: 11/08/2020 Updated: 14/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

django-celery-results up to and including 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

django-celery-results project django-celery-results

Vendor Advisories

Debian Bug report logs - #968305 python-django-celery-results: CVE-2020-17495 Package: src:python-django-celery-results; Maintainer for src:python-django-celery-results is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 12 Aug 2 ...