Information Exposure Affecting beaker package, versions [0.5,1.6.4)
Threat Intelligence
EPSS
0.37% (73rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-BEAKER-40102
- published 15 Sep 2012
- disclosed 15 Sep 2012
- credit Unknown
Introduced: 15 Sep 2012
CVE-2012-3458 Open this link in a new tabHow to fix?
Upgrade beaker
to version 1.6.4 or higher.
Overview
beaker
is a Session and Caching library with WSGI Middleware
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
References
CVSS Scores
version 3.1