devpi-server@2.0.2

devpi-server: backend for hosting private package indexes and PyPI on-demand mirrors

  • latest version

    6.20.3

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    3 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the devpi-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Missing Critical Step in Authentication

    devpi-server is a devpi-server: backend for hosting private package indexes and PyPI on-demand mirrors

    Affected versions of this package are vulnerable to Missing Critical Step in Authentication via the +changelog route when the replication protocol is enabled with the primary role. An attacker can access sensitive database contents, including password hashes and token information, by sending a specially crafted GET request. This can also lead to increased CPU, IO, and bandwidth usage depending on the database size. This is only exploitable if the server instance is configured with the replication protocol enabled using the primary (or deprecated master) role.

    How to fix Missing Critical Step in Authentication?

    Upgrade devpi-server to version 6.20.2 or higher.

    [,6.20.2)