CVE-2023-33185
These requests are signed by AWS and are verified by django_ses, however the verification of this signature was found to be flawed as it allowed users to specify arbitrary public certificates.
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests are signed by AWS and are verified by django_ses, however the verification of this signature was found to be flawed as it allowed users to specify arbitrary public certificates. This issue was patched in version 3.5.0.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- django-ses project/django-ses
- Source
- security-advisories@github.com
References
- https://github.com/django-ses/django-ses/blob/3d627067935876487f9938310d5e1fbb249a7778/CVE/001-cert-url-signature-verification.mdExploit, Third Party Advisory
- https://github.com/django-ses/django-ses/commit/b71b5f413293a13997b6e6314086cb9c22629795Patch
- https://github.com/django-ses/django-ses/security/advisories/GHSA-qg36-9jxh-fj25Vendor Advisory
- https://github.com/django-ses/django-ses/blob/3d627067935876487f9938310d5e1fbb249a7778/CVE/001-cert-url-signature-verification.mdExploit, Third Party Advisory
- https://github.com/django-ses/django-ses/commit/b71b5f413293a13997b6e6314086cb9c22629795Patch
- https://github.com/django-ses/django-ses/security/advisories/GHSA-qg36-9jxh-fj25Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.