Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like user email address in staff-authenticated requests.
This issue has been patched in versions 3.1.48, 3.7.59, 3.8.30, 3.9.27, 3.10.14 and 3.11.12.
None
If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-209"
],
"github_reviewed": true,
"github_reviewed_at": "2023-03-03T22:46:04Z",
"nvd_published_at": "2023-03-02T19:15:00Z",
"severity": "MODERATE"
}