PyPi: Ethyca-Fides

CVE-2024-52008

Safety vulnerability ID: 74436

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Nov 26, 2024 Updated at Dec 12, 2024
Scan your Python projects for vulnerabilities →

Advisory

Versions ethyca-fides are vulnerable to Client-Side Enforcement of Server-Side Security (CWE-602). The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set weak passwords by bypassing client-side validations. This vulnerability enables attackers to compromise accounts through brute-force or guessing attacks using easily obtainable passwords.

Affected package

ethyca-fides

Latest version: 2.51.1

Open-source ecosystem for data privacy as code.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application