Property
Languagepython
Severitymedium
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelMedium

Description#

The security context for Dask (distributed.security.Security) is being initialized without enabling encryption (require_encryption=False), which means data may be sent over the network in plain text. This exposes sensitive information to anyone who can intercept the network traffic.

Impact#

Without encryption, attackers could eavesdrop on or manipulate sensitive data transmitted between Dask components, leading to data breaches, credential theft, or unauthorized access. This can compromise the confidentiality and integrity of your distributed computations and sensitive user data.