VDB
Sign up
—

PYSEC-2018-7

Quick fix

PYSEC-2018-7 — django-anymail: upgrade to the fixed version with the command below.

pip install --upgrade 'django-anymail>=db586ede1fbb41dce21310ea28ae15a1cf1286c5'

Details

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/django-anymail
Introduced in: 0Fixed in: db586ede1fbb41dce21310ea28ae15a1cf1286c5
Fixpip install --upgrade 'django-anymail>=db586ede1fbb41dce21310ea28ae15a1cf1286c5'

References