VDB
KO
MEDIUM

GHSA-2vhw-q7vh-7xv2

openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers

Quick fix

GHSA-2vhw-q7vh-7xv2 — openssl-encrypt: upgrade to the fixed version with the command below.

pip install --upgrade 'openssl-encrypt>=1.4.0'

Details

### Summary

The `/ready` endpoint in `openssl_encrypt_server/server.py` at **lines 159-175** catches database errors and returns the full exception string in the response.

### Affected Code

```python except Exception as e: return {"status": "not_ready", "reason": str(e)} ```

### Impact

Database exception messages can leak: - Database hostnames and IP addresses - Connection parameters and port numbers - Driver version information - Potentially database credentials if included in connection string errors

This information is available to unauthenticated callers.

### Recommended Fix

- Return a generic error message: `{"status": "not_ready", "reason": "database unavailable"}` - Log the full exception server-side for debugging

### Fix

Fixed in commit `7aa8787` on branch `releases/1.4.x` — replaced str(e) with generic "database check failed" message; full exception logged server-side at WARNING level.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / openssl-encrypt
Introduced in: 0 Fixed in: 1.4.0
Fix pip install --upgrade 'openssl-encrypt>=1.4.0'

References