USN-2311-1

Source
https://ubuntu.com/security/notices/USN-2311-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2311-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2311-1
Related
Published
2014-08-11T17:20:19.513145Z
Modified
2014-08-11T17:20:19.513145Z
Summary
python-pycadf vulnerability
Details

Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens. An attacker could possibly use this issue to obtain authentication tokens used in REST requests.

References

Affected packages

Ubuntu:14.04:LTS / python-pycadf

Package

Name
python-pycadf
Purl
pkg:deb/ubuntu/python-pycadf?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.1-0ubuntu1.1

Affected versions

0.*

0.2-1
0.2-1build1
0.4.1-0ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "0.4.1-0ubuntu1.1",
            "binary_name": "python-pycadf"
        }
    ]
}