Skip to content

mycli has Inadequate Encryption Strength

Moderate severity GitHub Reviewed Published Oct 20, 2023 to the GitHub Advisory Database • Updated Nov 7, 2023

Package

pip mycli (pip)

Affected versions

<= 1.27.0

Patched versions

None

Description

Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py.

References

Published by the National Vulnerability Database Oct 19, 2023
Published to the GitHub Advisory Database Oct 20, 2023
Reviewed Oct 20, 2023
Last updated Nov 7, 2023

Severity

Moderate

EPSS score

0.068%
(30th percentile)

Weaknesses

CVE ID

CVE-2023-44690

GHSA ID

GHSA-v9vj-9pxv-mr2w

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.