CVE-2018-6596
published 2018-02-03CVE-2018-6596: webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows…
PriorityP349critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
2.61%
83.8th percentile
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | django-anymail | < django-anymail 1.3-1 (bookworm) | django-anymail 1.3-1 (bookworm) |
| django-anymail_project | django-anymail | < 1.2.1 | 1.2.1 |
| django-anymail_project | django-anymail | >= 0 < 1.3-1 | 1.3-1 |
| django-anymail_project | django-anymail | >= 0 < 1.3-1 | 1.3-1 |
| django-anymail_project | django-anymail | >= 0 < 1.3-1 | 1.3-1 |
| django-anymail_project | django-anymail | >= 0 < 1.3-1 | 1.3-1 |
| django-anymail_project | django-anymail | >= 0 < 1.2.1 | 1.2.1 |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-6596: django-anymail - webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timi...
vendor_debian·2018·CVSS 9.1
CVE-2018-6596 [CRITICAL] CVE-2018-6596: django-anymail - webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timi...
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
Scope: local
bookworm: resolved (fixed in 1.3-1)
bullseye: resolved (fixed in 1.3-1)
forky: resolved (fixed in 1.3-1)
sid: resolved (fixed in 1.3-1)
trixie: resolved (fixed in 1.3-1)
OSV
Django-Anymail prone to a timing attack
osv·2018-07-12
CVE-2018-6596 [CRITICAL] Django-Anymail prone to a timing attack
Django-Anymail prone to a timing attack
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
GHSA
Django-Anymail prone to a timing attack
ghsa·2018-07-12
CVE-2018-6596 [CRITICAL] CWE-200 Django-Anymail prone to a timing attack
Django-Anymail prone to a timing attack
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
OSV
CVE-2018-6596: webhooks/base
osv·2018-02-03·CVSS 9.1
CVE-2018-6596 [CRITICAL] CVE-2018-6596: webhooks/base
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/889450https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691bhttps://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15a1cf1286c5https://github.com/anymail/django-anymail/releases/tag/v1.2.1https://github.com/anymail/django-anymail/releases/tag/v1.3https://www.debian.org/security/2018/dsa-4107https://bugs.debian.org/889450https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691bhttps://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15a1cf1286c5https://github.com/anymail/django-anymail/releases/tag/v1.2.1https://github.com/anymail/django-anymail/releases/tag/v1.3https://www.debian.org/security/2018/dsa-4107
2018-02-03
Published