Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwr5-q9rx-294f

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Improper query string handling in Django

The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.1.3

1.1.3

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.2, < 1.2.4

1.2.4

EPSS

Процентиль: 67%
0.00553
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 14 лет назад

The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.

nvd
больше 14 лет назад

The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.

debian
больше 14 лет назад

The administrative interface in django.contrib.admin in Django before ...

EPSS

Процентиль: 67%
0.00553
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-20