Bug#890097: src:django-anymail: New, minor WEBHOOK_AUTHORIZATION security issue

2018-03-10 Thread Salvatore Bonaccorso
Hi, On Sun, Feb 11, 2018 at 01:08:01AM -0500, Scott Kitterman wrote: > Given that the fix for this is problematic from a backward compatility > perspective and that it requires a misconfigured django app before it is a > problem, recommend No DSA for the security team. Scott, sorry we did not

Bug#890097: src:django-anymail: New, minor WEBHOOK_AUTHORIZATION security issue

2018-02-22 Thread Scott Kitterman
On Sun, 11 Feb 2018 01:08:01 -0500 Scott Kitterman wrote: > Package: src:django-anymail > Version: 0.8-2 > Severity: important > Tags: upstream,security > > Security fix > > This fixes a low severity security issue affecting Anymail v0.2–v1.3. (CVE > Pending) > > Django

Bug#890097: src:django-anymail: New, minor WEBHOOK_AUTHORIZATION security issue

2018-02-10 Thread Scott Kitterman
Package: src:django-anymail Version: 0.8-2 Severity: important Tags: upstream,security Security fix This fixes a low severity security issue affecting Anymail v0.2–v1.3. (CVE Pending) Django error reporting includes the value of your Anymail WEBHOOK_AUTHORIZATION setting. In a