{"id":"GHSA-879p-8gw4-mcpw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-879p-8gw4-mcpw","summary":" fgr Vulnerable to Insecure Default Variable Initialization","details":"### Impact\nAny users whom would not desire a traceback to be included in their logs whenever an error is raised in their code will be affected.\n\nIf users have inadvertently created a scenario in their code that could cause a traceback to include sensitive information _and_ a malicious entity gained access to their log stream, this could create an issue.\n\n### Patches\nNone yet... users will need to upgrade to `0.4.*`\n\n### Workarounds\nNo particularly reasonable ones at present.\n\n### References\n* https://cwe.mitre.org/data/definitions/453.html\n* https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/stack-trace-disclosure-python/","published":"2024-03-15T19:01:10Z","modified":"2024-12-04T05:40:18.796535Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"fgr","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/dan1hc/fgr/security/advisories/GHSA-879p-8gw4-mcpw"},{"type":"PACKAGE","url":"https://github.com/dan1hc/fgr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:40:18.796535Z"}}