Information Exposure The advisory has been revoked - it doesn't affect any version of package mycli  (opens in a new tab)


Threat Intelligence

EPSS
0.13% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-MYCLI-6016649
  • published20 Oct 2023
  • disclosed19 Oct 2023
  • creditgxx777

Introduced: 19 Oct 2023

CVE-2023-44690  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

There is no fixed version for mycli.

Amendment

This was deemed not a vulnerability.

Overview

mycli is a CLI for MySQL Database. With auto-completion and syntax highlighting.

Affected versions of this package are vulnerable to Information Exposure through the /mycli/config.py endpoint. An attacker can view sensitive information by exploiting the inadequate encryption strength.

Note: This is only exploitable if the attacker has access to the /mycli/config.py endpoint.

References