{"id":"GHSA-879p-8gw4-mcpw","summary":" fgr Vulnerable to Insecure Default Variable Initialization","details":"### Impact\nAny users whom would not desire a traceback to be included in their logs whenever an error is raised in their code will be affected.\n\nIf users have inadvertently created a scenario in their code that could cause a traceback to include sensitive information _and_ a malicious entity gained access to their log stream, this could create an issue.\n\n### Patches\nNone yet... users will need to upgrade to `0.4.*`\n\n### Workarounds\nNo particularly reasonable ones at present.\n\n### References\n* https://cwe.mitre.org/data/definitions/453.html\n* https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/stack-trace-disclosure-python/","modified":"2024-12-04T05:40:18.796535Z","published":"2024-03-15T19:01:10Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-453"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-03-15T19:01:10Z"},"references":[{"type":"WEB","url":"https://github.com/dan1hc/fgr/security/advisories/GHSA-879p-8gw4-mcpw"},{"type":"PACKAGE","url":"https://github.com/dan1hc/fgr"}],"affected":[{"package":{"name":"fgr","ecosystem":"PyPI","purl":"pkg:pypi/fgr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.3.2"}]}],"versions":["0.1.4","0.1.5","0.1.6","0.1.7","0.1.7rc1","0.2.0","0.2.0rc1","0.2.1","0.3.0","0.3.0rc1","0.3.0rc2","0.3.1","0.3.2","0.3.2rc1","0.3.2rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-879p-8gw4-mcpw/GHSA-879p-8gw4-mcpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}