Django-Anymail prone to a timing attack
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Jul 12, 2018 
          to the GitHub Advisory Database
          •
          Updated Sep 16, 2024 
      
  
Description
        Published to the GitHub Advisory Database
      Jul 12, 2018 
    
  
        Reviewed
      Jun 16, 2020 
    
  
        Last updated
      Sep 16, 2024 
    
  
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
References