CVE-2020-4045: Information Exposure
(updated )
SSB-DB has an information disclosure vulnerability. The get()
method is supposed to only decrypt messages when you explicitly ask it to, but there is a bug where it’s decrypting any message that it can.
References
Detect and mitigate CVE-2020-4045 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →