QID 995370
Date Published: 2023-09-25
QID 995370: Python (Pip) Security Update for duplicity (GHSA-wxcw-rqxc-hj85)
The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wxcw-rqxc-hj85 for updates and patch information.
Vendor References
- GHSA-wxcw-rqxc-hj85 -
github.com/advisories/GHSA-wxcw-rqxc-hj85
CVEs related to QID 995370
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wxcw-rqxc-hj85 | duplicity |
|