Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack prior to 0.1.30.
The product uses hard-coded constants instead of symbolic names for security-critical values, which increases the likelihood of mistakes during code maintenance or security policy change.
Link | Tags |
---|---|
https://huntr.dev/bounties/9a6b1fb4-ec9b-4cfa-af1e-9ce304924829 | patch exploit third party advisory issue tracking |
https://github.com/deepset-ai/haystack/commit/5fc84904f198de661d5b933fde756aa922bf09f1 | patch |