Webhook Authorization Vulnerability in Anymail by Anymail
CVE-2018-1000089
7.4HIGH
What is CVE-2018-1000089?
The Anymail Django library, versions 0.2 through 1.3, has a vulnerability in the WEBHOOK_AUTHORIZATION setting that may allow attackers with access to error logs to fabricate email tracking events. If Django error reports are exposed, an attacker could potentially discover the ANYMAIL_WEBHOOK setting and exploit it to submit forged or malicious tracking events to the application. This issue was addressed in version 1.4.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved