Information Leakage Affecting fastapi package, versions [0.36.0, 0.37.0)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-FASTAPI-569038
- published 13 May 2020
- disclosed 1 Apr 2020
- credit Unknown
How to fix?
Upgrade fastapi
to version 0.37.0 or higher.
Overview
fastapi is a web framework for building APIs with Python 3.6+ based on standard Python type hints.
Affected versions of this package are vulnerable to Information Leakage. When returning a sub-class of a response model and using skip_defaults
it could leak information.
References
CVSS Scores
version 3.1