Filtered by vendor Backblaze
Subscribe
Filtered by product B2 Python Software Development Kit
Subscribe
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-23651 | 1 Backblaze | 1 B2 Python Software Development Kit | 2024-11-21 | 1.9 LOW | 4.7 MEDIUM |
|
b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK version 1.14.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. SDK users of the SqliteAccountInfo format are vulnerable while users of the InMemoryAccountInfo format are safe. The SqliteAccountInfo saves API keys (and bucket name-to-id mapping) in a local da ...
Show More |
|||||