logo

GHSA-879p-8gw4-mcpw fgr

Package

Manager: pip
Name: fgr
Vulnerable Version: >=0 <=0.3.2

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: N/A pctlN/A

Details

fgr Vulnerable to Insecure Default Variable Initialization ### Impact Any users whom would not desire a traceback to be included in their logs whenever an error is raised in their code will be affected. If users have inadvertently created a scenario in their code that could cause a traceback to include sensitive information _and_ a malicious entity gained access to their log stream, this could create an issue. ### Patches None yet... users will need to upgrade to `0.4.*` ### Workarounds No particularly reasonable ones at present. ### References * https://cwe.mitre.org/data/definitions/453.html * https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/stack-trace-disclosure-python/

Metadata

Created: 2024-03-15T19:01:10Z
Modified: 2024-03-15T19:01:10Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-879p-8gw4-mcpw/GHSA-879p-8gw4-mcpw.json
CWE IDs: ["CWE-453"]
Alternative ID: N/A
Finding: F124
Auto approve: 1