CVE-2020-17495
Summary
| CVE | CVE-2020-17495 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-11 21:15:00 UTC |
| Updated | 2020-08-14 20:09:00 UTC |
| Description | django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Question: Disable storing of task arguments · Issue #142 · celery/django-celery-results · GitHub |
MISC |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982359 Python (pip) Security Update for django-celery-results (GHSA-fvx8-v524-8579)