GHSA-2vhw-q7vh-7xv2
openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers
Quick fix
GHSA-2vhw-q7vh-7xv2 — openssl-encrypt: upgrade to the fixed version with the command below.
pip install --upgrade 'openssl-encrypt>=1.4.0' Details
### Summary
The `/ready` endpoint in `openssl_encrypt_server/server.py` at **lines 159-175** catches database errors and returns the full exception string in the response.
### Affected Code
```python except Exception as e: return {"status": "not_ready", "reason": str(e)} ```
### Impact
Database exception messages can leak: - Database hostnames and IP addresses - Connection parameters and port numbers - Driver version information - Potentially database credentials if included in connection string errors
This information is available to unauthenticated callers.
### Recommended Fix
- Return a generic error message: `{"status": "not_ready", "reason": "database unavailable"}` - Log the full exception server-side for debugging
### Fix
Fixed in commit `7aa8787` on branch `releases/1.4.x` — replaced str(e) with generic "database check failed" message; full exception logged server-side at WARNING level.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 1.4.0 pip install --upgrade 'openssl-encrypt>=1.4.0'