—
PYSEC-2020-229
Quick fix
PYSEC-2020-229 — django-nopassword: upgrade to the fixed version with the command below.
pip install --upgrade 'django-nopassword>=d8b4615f5fbfe3997d96cf4cb3e342406396193c'Details
django-nopassword before 5.0.0 stores cleartext secrets in the database.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/django-nopassword
Introduced in:
0Fixed in: d8b4615f5fbfe3997d96cf4cb3e342406396193cFix
pip install --upgrade 'django-nopassword>=d8b4615f5fbfe3997d96cf4cb3e342406396193c'References
- https://github.com/relekang/django-nopassword/commit/d8b4615f5fbfe3997d96cf4cb3e342406396193c[FIX]
- https://github.com/relekang/django-nopassword/blob/8e8cfc765ee00adfed120c2c79bf71ef856e9022/nopassword/models.py#L14[WEB]
- https://github.com/relekang/django-nopassword/compare/v4.0.1...v5.0.0[WEB]
- https://github.com/advisories/GHSA-37cf-r3w2-gjfw[ADVISORY]