MEDIUMPyPI →
Incorrect signature verification in django-ses
Incorrect signature verification in django-ses
Affected packages
- django-ses— before 3.5.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/django-ses/django-ses/security/advisories/GHSA-qg36-9jxh-fj25
- https://nvd.nist.gov/vuln/detail/CVE-2023-33185
- https://github.com/django-ses/django-ses/commit/b71b5f413293a13997b6e6314086cb9c22629795
- https://github.com/django-ses/django-ses
- https://github.com/django-ses/django-ses/blob/3d627067935876487f9938310d5e1fbb249a7778/CVE/001-cert-url-signature-verification.md
- https://github.com/pypa/advisory-database/tree/main/vulns/django-ses/PYSEC-2023-82.yaml
Structured record: https://osv.dev/vulnerability/GHSA-qg36-9jxh-fj25
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta