Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.6 PyPI

rdiffweb vulnerable to Use of Cache Containing Sensitive Information

GHSA-7fqm-jm52-f9vc · CVE-2022-3292 · PYSEC-2022-296

Published · Modified

Description

rdiffweb prior to version 2.4.9 is vulnerable to Use of Cache Containing Sensitive Information. Due to improper cache control, an attacker can view sensitive information even if they are not logged into an account. Version 2.4.9 contains a patch for this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes