VDB
Sign up
—

PYSEC-2012-1

Quick fix

PYSEC-2012-1 — beaker: upgrade to the fixed version with the command below.

pip install --upgrade 'beaker>=91becae76101cf87ce8cbfabe3af2622fc328fe5'

Details

Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/beaker
Introduced in: 0Fixed in: 91becae76101cf87ce8cbfabe3af2622fc328fe5
Fixpip install --upgrade 'beaker>=91becae76101cf87ce8cbfabe3af2622fc328fe5'

References