CVE-2018-1000089 describes a vulnerability in django-anymail versions 0.2 through 1.3, where sensitive information from the WEBHOOK_AUTHORIZATION setting could be exposed in error logs. An attacker with access to these logs could discover the ANYMAIL_WEBHOOK setting, enabling them to fabricate email tracking or inbound events. This vulnerability carries a CVSS score of 7.4 (HIGH), indicating a network-based attack with high impact on confidentiality and integrity, but requiring high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.2, <= 1.3CPE matchmatch criteria | cpe:2.3:a:django-anymail_project:django-anymail:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.