Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6wcr-wcqm-3mfh

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 2.8

Описание

Django settings leak in date template filter

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.7, < 1.7.11

1.7.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.8a1, < 1.8.7

1.8.7

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.9a1, < 1.9rc2

1.9rc2

EPSS

Процентиль: 86%
0.03006
Низкий

6.9 Medium

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

redhat
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

nvd
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

debian
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x bef ...

EPSS

Процентиль: 86%
0.03006
Низкий

6.9 Medium

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-200