PyPi: Ethyca-Fides

CVE-2024-34715

Safety vulnerability ID: 71967

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at May 29, 2024 Updated at Dec 12, 2024
Scan your Python projects for vulnerabilities →

Advisory

Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If the password used by the web server for this database connection includes special characters such as `@` and `$`, the webserver startup fails and the part of the password following the special character is exposed in web server error logs. This is caused by improper escaping of the SQLAlchemy password string. As a result, users are subject to partial exposure of hosted database passwords in web server logs.

Affected package

ethyca-fides

Latest version: 2.51.1

Open-source ecosystem for data privacy as code.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application