Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0305

Опубликовано: 19 фев. 2013
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 2.1Django14Affected
Red Hat Subscription Asset ManagerDjangoAffected
RHOS Essex ReleaseDjangoAffected
OpenStack Folsom for RHEL 6Django14FixedRHSA-2013:067021.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=913041Django: Data leakage via admin history log

EPSS

Процентиль: 44%
0.00209
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

nvd
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

debian
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS3: 4.3
github
около 3 лет назад

Django Data leakage via admin history log

EPSS

Процентиль: 44%
0.00209
Низкий

4 Medium

CVSS2