{"id":"PYSEC-2020-229","details":"django-nopassword before 5.0.0 stores cleartext secrets in the database.","aliases":["CVE-2019-10682","GHSA-37cf-r3w2-gjfw"],"modified":"2023-11-08T04:00:54.165036Z","published":"2020-03-18T15:15:00Z","references":[{"type":"FIX","url":"https://github.com/relekang/django-nopassword/commit/d8b4615f5fbfe3997d96cf4cb3e342406396193c"},{"type":"WEB","url":"https://github.com/relekang/django-nopassword/blob/8e8cfc765ee00adfed120c2c79bf71ef856e9022/nopassword/models.py#L14"},{"type":"WEB","url":"https://github.com/relekang/django-nopassword/compare/v4.0.1...v5.0.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-37cf-r3w2-gjfw"}],"affected":[{"package":{"name":"django-nopassword","ecosystem":"PyPI","purl":"pkg:pypi/django-nopassword"},"ranges":[{"type":"GIT","repo":"https://github.com/relekang/django-nopassword","events":[{"introduced":"0"},{"fixed":"d8b4615f5fbfe3997d96cf4cb3e342406396193c"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.0"}]}],"versions":["0.1.2","0.2","0.3","0.3.1","0.3.2","0.3.3","0.4","0.4.1","0.4.2","0.4.3","0.5.0","0.6.0","0.7.0","0.8.0","1.0.0","1.1.0","1.2.0","1.3.0","1.3.1","2.0.0","2.1.0","2.1.1","3.0.0","3.0.1","3.0.2","4.0.0","4.0.1","4.0.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django-nopassword/PYSEC-2020-229.yaml"}}],"schema_version":"1.7.3"}