pulpcore is vulnerable to Generation of Error Message Containing Sensitive Information
20
Low Risk
Affected versions of this package are vulnerable to information disclosure via exception tracebacks from failed tasks, where tracebacks expose sensitive data such as internal system paths or configuration details through the API. An attacker could exploit this by repeatedly triggering task failures or querying the API to access these tracebacks, thereby extracting confidential information.
You are affected if you are using a version that falls within the vulnerable range.
pulpcore is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.0.0 - 3.101.0.
Upgrade the pulpcore library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant