QID 671044
Date Published: 2021-11-30
QID 671044: EulerOS Security Update for python-beaker (EulerOS-SA-2021-2608)
Beaker is a caching library that includes session and cache objects built on myghty's container api used in myghtyutils.
Wsgi middleware is also included to manage session objects and signed cookies.
Security fix(es): beaker before 1.6.4, when using pycrypto to encrypt sessions, uses aes in ecb cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.(cve-2012-3458)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
Solution
The Vendor has released a security update to fix the vulnerability. For more information please visit EulerOS-SA-2021-2608 for updates and patch information
Vendor References
CVEs related to QID 671044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2608 | EulerOS V2.0SP3 |
|