QID 995702

Date Published: 2023-10-25

QID 995702: Python (Pip) Security Update for ethyca-fides (GHSA-fgjj-5jmr-gh83)

The Fides web application allows users to edit consent and privacy notices such as cookie banners. These privacy notices can then be served by other integrated websites, for example in cookie consent banners. One of the editable fields is a privacy policy URL and this input was found to not be validated.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-fgjj-5jmr-gh83 for updates and patch information.
    Vendor References

    CVEs related to QID 995702

    Software Advisories
    Advisory ID Software Component Link
    GHSA-fgjj-5jmr-gh83 ethyca-fides URL Logo github.com/advisories/GHSA-fgjj-5jmr-gh83