Vulnerability Bulletins

DSA-4107 django-anymail - security update

   
Affected software Debian
 
It was discovered that the webhook validation of Anymail, a Django emailbackends for multiple ESPs, is prone to a timing attack. A remoteattacker can take advantage of this flaw to obtain aWEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.

More info:

https://www.debian.org/security/2018/dsa-4107