PYSEC-2020-38

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django-celery-results/PYSEC-2020-38.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2020-38
Aliases
Published
2020-08-11T21:15:00Z
Modified
2023-11-01T04:52:09.553437Z
Summary
[none]
Details

django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.

References

Affected packages

PyPI / django-celery-results

Package

Name
django-celery-results
View open source insights on deps.dev
Purl
pkg:pypi/django-celery-results

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.0

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1