QID 995863

Date Published: 2023-11-16

QID 995863: Python (Pip) Security Update for ethyca-fides (GHSA-3vpf-mcj7-5h38)

The Fides web application allows data subject users to request access to their personal data. If the request is approved by the data controller user operating the Fides web application, the data subject's personal data can then retrieved from connected systems and data stores before being bundled together as a data subject access request package for the data subject to download. Supported data formats for the package include json and csv, but the most commonly used format is a series of HTML files compressed in a ZIP file. Once downloaded and unzipped, the data subject user can browse the HTML files on their local machine.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-3vpf-mcj7-5h38 for updates and patch information.
    Vendor References

    CVEs related to QID 995863

    Software Advisories
    Advisory ID Software Component Link
    GHSA-3vpf-mcj7-5h38 ethyca-fides URL Logo github.com/advisories/GHSA-3vpf-mcj7-5h38