
Cloud Vulnerability DB
A community-led vulnerabilities database
django-celery-results through version 1.2.1 contains a security vulnerability where task results are stored in the database, including variables passed into the tasks. This potentially exposes sensitive information as the variables may contain cleartext data that should not be stored unencrypted in the database (NVD).
The vulnerability has been assigned CVE-2020-17495 with a CVSS v3.1 base score of 7.5 (HIGH) and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The issue stems from the django-celery-results package storing task execution variables in cleartext form in the database, which could expose sensitive information passed as arguments to Celery tasks (NVD).
The vulnerability could lead to exposure of sensitive information if task arguments contain confidential data, as this data would be stored unencrypted in the database. This creates a potential security risk if the database is compromised or accessed by unauthorized users (NVD).
The vulnerability is remotely exploitable without authentication. An attacker with access to the database could potentially view sensitive information stored in cleartext form as task arguments (NVD).
The issue was disputed by upstream developers as a security vulnerability, noting that it is up to developers using celery tasks to provide suitable replacement arguments through argsrepr and kwargsrepr when handling sensitive information. This allows developers to control what information gets stored in the database (Debian).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."