Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7w6-p47g-vj53

Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Django Data leakage via admin history log

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.3, < 1.3.6

1.3.6

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.4, < 1.4.4

1.4.4

EPSS

Процентиль: 44%
0.00209
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

redhat
больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

nvd
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

debian
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

EPSS

Процентиль: 44%
0.00209
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200