CVE-2020-17495
Python vulnerability analysis and mitigation

Overview

django-celery-results through version 1.2.1 contains a security vulnerability where task results are stored in the database, including variables passed into the tasks. This potentially exposes sensitive information as the variables may contain cleartext data that should not be stored unencrypted in the database (NVD).

Technical details

The vulnerability has been assigned CVE-2020-17495 with a CVSS v3.1 base score of 7.5 (HIGH) and vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The issue stems from the django-celery-results package storing task execution variables in cleartext form in the database, which could expose sensitive information passed as arguments to Celery tasks (NVD).

Impact

The vulnerability could lead to exposure of sensitive information if task arguments contain confidential data, as this data would be stored unencrypted in the database. This creates a potential security risk if the database is compromised or accessed by unauthorized users (NVD).

Exploitability

The vulnerability is remotely exploitable without authentication. An attacker with access to the database could potentially view sensitive information stored in cleartext form as task arguments (NVD).

Mitigation and workarounds

The issue was disputed by upstream developers as a security vulnerability, noting that it is up to developers using celery tasks to provide suitable replacement arguments through argsrepr and kwargsrepr when handling sensitive information. This allows developers to control what information gets stored in the database (Debian).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61539CRITICAL10
  • Python logoPython
  • xinference
NoYesAug 21, 2026
CVE-2026-49360HIGH7.8
  • Python logoPython
  • recce
NoYesAug 21, 2026
CVE-2026-68508HIGH7.8
  • Python logoPython
  • hydra-core
NoYesAug 21, 2026
CVE-2026-43980MEDIUM6.3
  • Python logoPython
  • malla
NoNoAug 21, 2026
CVE-2026-55468MEDIUM4.3
  • Python logoPython
  • wagtail
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management