{"id":"CVE-2023-44690","aliases":["GHSA-v9vj-9pxv-mr2w","PYSEC-2023-213"],"title":"mycli has Inadequate Encryption Strength","summary":"mycli has Inadequate Encryption Strength","severity":"medium","vendor":"mycli","product":"mycli","ecosystem":"pip","affected":["mycli <= 1.27.0"],"published":"2023-10-20","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:08.730926512Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v9vj-9pxv-mr2w","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44690"},{"url":"https://github.com/dbcli/mycli/issues/1131"},{"url":"https://github.com/dbcli/mycli"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/mycli/PYSEC-2023-213.yaml"}],"tags":["osv","pip"],"epss":0.00222,"epssPercentile":0.12982,"ingestedAt":"2026-09-12T03:13:01.730Z","slug":"CVE-2023-44690","body":"## Overview\n\nInadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via `/mycli/config.py`.\n\n## Affected packages\n\n- `mycli <= 1.27.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}