Description
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

A weakness in an unknown function of the backend/sxdevops/settings.py file allows an attacker to manipulate the file contents and cause exposure of sensitive configuration data. The flaw results in disclosure of confidential information that should not be publicly visible. The data exposed may include credentials, environment variables, or other secrets. The vulnerability is classified as Information Disclosure and is related to both CWE-200 (Sensitive Data Exposure) and CWE‑284 (Improper Access Control).

Affected Systems

The vulnerability affects aiyiyi121 SxDevOps 1.0 and 1.1. Users of these versions are at risk if the backend/sxdevops/settings.py file can be accessed or altered by an unauthorized party.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity impact. As the EPSS score is not available, there is no published exploitation probability, but the fact that the attack can be initiated remotely raises concern. The vulnerability is not listed in the CISA KEV catalog, which suggests no publicly known exploit targets, yet the remote nature of the attack vector increases the risk. Organizations should assume that an attacker could compromise confidentiality if the settings file is not adequately protected. Inferences: The attack can be performed from any remote host with network access to the server environment where SxDevOps is running. The precise exploitation steps are not detailed in the description, so the vector is inferred rather than explicitly stated.

Generated by OpenCVE AI on September 20, 2026 at 08:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor patch commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9 for SxDevOps 1.0 or 1.1
  • Restrict file permissions on backend/sxdevops/settings.py so that only privileged users can read it, limiting exposure to unauthorized access
  • Enable monitoring or logging of attempts to read or modify backend/sxdevops/settings.py and investigate any suspicious activity

Generated by OpenCVE AI on September 20, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps settings.py information disclosure
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T07:30:11.081Z

Reserved: 2026-09-19T10:15:05.248Z

Link: CVE-2026-93971

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-20T08:16:51.257

Modified: 2026-09-20T08:16:51.257

Link: CVE-2026-93971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control