Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2018-6596
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.005
EPSS Ranking
65.2%
CVSS Severity
CVSS v3 Score
9.1
CVSS v2 Score
6.4
References
https://bugs.debian.org/889450
https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691b
https://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15a1cf1286c5
https://github.com/anymail/django-anymail/releases/tag/v1.2.1
https://github.com/anymail/django-anymail/releases/tag/v1.3
https://www.debian.org/security/2018/dsa-4107
https://bugs.debian.org/889450
https://github.com/anymail/django-anymail/commit/c07998304b4a31df4c61deddcb03d3607a04691b
https://github.com/anymail/django-anymail/commit/db586ede1fbb41dce21310ea28ae15a1cf1286c5
https://github.com/anymail/django-anymail/releases/tag/v1.2.1
https://github.com/anymail/django-anymail/releases/tag/v1.3
https://www.debian.org/security/2018/dsa-4107
Products affected by CVE-2018-6596
Django-Anymail Project
»
Django-Anymail
»
Version:
0.1
cpe:2.3:a:django-anymail_project:django-anymail:0.1
Django-Anymail Project
»
Django-Anymail
»
Version:
0.10
cpe:2.3:a:django-anymail_project:django-anymail:0.10
Django-Anymail Project
»
Django-Anymail
»
Version:
0.11
cpe:2.3:a:django-anymail_project:django-anymail:0.11
Django-Anymail Project
»
Django-Anymail
»
Version:
0.11.1
cpe:2.3:a:django-anymail_project:django-anymail:0.11.1
Django-Anymail Project
»
Django-Anymail
»
Version:
0.2
cpe:2.3:a:django-anymail_project:django-anymail:0.2
Django-Anymail Project
»
Django-Anymail
»
Version:
0.3
cpe:2.3:a:django-anymail_project:django-anymail:0.3
Django-Anymail Project
»
Django-Anymail
»
Version:
0.3.1
cpe:2.3:a:django-anymail_project:django-anymail:0.3.1
Django-Anymail Project
»
Django-Anymail
»
Version:
0.4
cpe:2.3:a:django-anymail_project:django-anymail:0.4
Django-Anymail Project
»
Django-Anymail
»
Version:
0.4.1
cpe:2.3:a:django-anymail_project:django-anymail:0.4.1
Django-Anymail Project
»
Django-Anymail
»
Version:
0.4.2
cpe:2.3:a:django-anymail_project:django-anymail:0.4.2
Django-Anymail Project
»
Django-Anymail
»
Version:
0.5
cpe:2.3:a:django-anymail_project:django-anymail:0.5
Django-Anymail Project
»
Django-Anymail
»
Version:
0.6
cpe:2.3:a:django-anymail_project:django-anymail:0.6
Django-Anymail Project
»
Django-Anymail
»
Version:
0.6.1
cpe:2.3:a:django-anymail_project:django-anymail:0.6.1
Django-Anymail Project
»
Django-Anymail
»
Version:
0.7
cpe:2.3:a:django-anymail_project:django-anymail:0.7
Django-Anymail Project
»
Django-Anymail
»
Version:
0.8
cpe:2.3:a:django-anymail_project:django-anymail:0.8
Django-Anymail Project
»
Django-Anymail
»
Version:
0.9
cpe:2.3:a:django-anymail_project:django-anymail:0.9
Django-Anymail Project
»
Django-Anymail
»
Version:
1.0
cpe:2.3:a:django-anymail_project:django-anymail:1.0
Django-Anymail Project
»
Django-Anymail
»
Version:
1.1
cpe:2.3:a:django-anymail_project:django-anymail:1.1
Django-Anymail Project
»
Django-Anymail
»
Version:
1.2
cpe:2.3:a:django-anymail_project:django-anymail:1.2
Debian
»
Debian Linux
»
Version:
9.0
cpe:2.3:o:debian:debian_linux:9.0
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved