CVE-2018-6596

Publication date 3 February 2018

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

9.1 · Critical

Score breakdown

Description

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

Status

Package Ubuntu Release Status
django-anymail 18.04 LTS bionic
Not affected
17.10 artful Ignored end of life
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.1 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities