GHSA-39vm-p9mr-4r27
Dashboard / Vulnerabilities / GHSA-39vm-p9mr-4r27
GHSA-39vm-p9mr-4r27
Summary: Beaker Sensitive Information Disclosure vulnerability
Details: Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
References: https://nvd.nist.gov/vuln/detail/CVE-2012-3458, https://github.com/bbangert/beaker/commit/91becae76101cf87ce8cbfabe3af2622fc328fe5, https://bugzilla.redhat.com/show_bug.cgi?id=809267, https://github.com/bbangert/beaker, https://github.com/pypa/advisory-database/tree/main/vulns/beaker/PYSEC-2012-1.yaml, https://web.archive.org/web/20140724164516/http://secunia.com/advisories/50226, https://web.archive.org/web/20140725025612/http://secunia.com/advisories/50520, http://www.debian.org/security/2012/dsa-2541, http://www.openwall.com/lists/oss-security/2012/08/13/10
Affected packages
Package
Name: beaker
Purl: pkg:pypi/beaker
Affected ranges
Type: ECOSYSTEM
Events:
