django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.
References
Link | Resource |
---|---|
https://github.com/celery/django-celery-results/issues/142 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-08-11 14:15
Updated : 2020-08-14 13:09
NVD link : CVE-2020-17495
Mitre link : CVE-2020-17495
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
django-celery-results_project
- django-celery-results