PyPi: Ethyca-Fides

CVE-2024-31223

Safety vulnerability ID: 72082

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jul 03, 2024 Updated at Dec 12, 2024
Scan your Python projects for vulnerabilities →

Advisory

Fides affected versions are vulnerable to a security issue involving the SERVER_SIDE_FIDES_API_URL configuration environment variable used by the Fides Privacy Center. This variable typically contains a URL with a private IP address, private domain name, and/or port. An unauthenticated attacker could exploit this vulnerability to make an HTTP GET request from the Privacy Center, disclosing the value of this server-side URL. This disclosure could provide the attacker with information on server-side ports, private IP addresses, and/or private domain names.

Affected package

ethyca-fides

Latest version: 2.51.1

Open-source ecosystem for data privacy as code.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application