Vulnerability Bulletins |
DSA-4107 django-anymail - security update |
|
| Affected software | Debian |
|
It was discovered that the webhook validation of Anymail, a Django emailbackends for multiple ESPs, is prone to a timing attack. A remoteattacker can take advantage of this flaw to obtain aWEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events. More info: https://www.debian.org/security/2018/dsa-4107 |
|






