Vulnerability Description
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Django-Anymail Project | Django-Anymail | < 1.2.1 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/889450Issue TrackingPatchThird Party Advisory
- https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d36Patch
- https://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15aPatch
- https://github.com/anymail/django-anymail/releases/tag/v1.2.1Release Notes
- https://github.com/anymail/django-anymail/releases/tag/v1.3Release Notes
- https://www.debian.org/security/2018/dsa-4107Third Party Advisory
- https://bugs.debian.org/889450Issue TrackingPatchThird Party Advisory
- https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d36Patch
- https://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15aPatch
- https://github.com/anymail/django-anymail/releases/tag/v1.2.1Release Notes
- https://github.com/anymail/django-anymail/releases/tag/v1.3Release Notes
- https://www.debian.org/security/2018/dsa-4107Third Party Advisory
FAQ
What is CVE-2018-6596?
CVE-2018-6596 is a vulnerability with a CVSS score of 9.1 (CRITICAL). webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail trac...
How severe is CVE-2018-6596?
CVE-2018-6596 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-6596?
Check the references section above for vendor advisories and patch information. Affected products include: Django-Anymail Project Django-Anymail, Debian Debian Linux.