Skip to content

Celery update to address CVE-2021-23727 #7076

Answered by nijel
ghubz asked this question in General
Discussion options

You must be logged in to vote

It should be safe to upgrade.

Please note that the vulnerability is not exploitable without access to the Celery results backend (for Weblate it is most likely redis). That would indicate severe security issue in the infrastructure, and the attacker would be most likely able to exploit that in simpler means than via CVE-2021-23727.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@ghubz
Comment options

@nijel
Comment options

nijel Jan 7, 2022
Maintainer

Answer selected by ghubz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants