celery is vulnerable to Insertion of Sensitive Information into Log File
25
Low Risk
Affected versions of this package may expose sensitive information in log files. When setting up delayed delivery, Celery logs the full broker URL —including the embedded username and password— directly to the DelayedDelivery consumer output. This results in credential leakage and violates standard security practices that prohibit storing secrets in logs.
You are affected if you are using a vulnerable version of the package.
celery is vulnerable to Insertion of Sensitive Information into Log File in versions 5.5.0 - 5.5.3.
Upgrade celery to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant