sqlalchemy-celery-beat is vulnerable to Information Disclosure
25
Low Risk
Affected versions of this package are affected by a security misconfiguration in the DatabaseScheduler class that exposes the entire database connection string, including the password, through the info property. It could lead to credential leaks in logs or outputs when Celery Beat starts, allowing an attacker to access sensitive data or compromise the system.
You are affected if you are using a version that falls within the vulnerable range.
sqlalchemy-celery-beat is vulnerable to Information Disclosure in versions 0.6.1 - 0.8.0.
Upgrade the sqlalchemy-celery-beat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant