Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8213

Опубликовано: 24 нояб. 2015
Источник: redhat
CVSS2: 4.3

Описание

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

An information-exposure flaw was found in the Django date filter. If an application allowed users to provide non-validated date formats, a malicious end user could expose application-settings data by providing the relevant applications-settings key instead of a valid date format.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2DjangoWill not fix
Red Hat Ceph Storage 1.3DjangoWill not fix
Red Hat OpenStack Platform 8 (Liberty)python-djangoNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational Toolspython-djangoNot affected
Red Hat Subscription Asset ManagerDjangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6python-djangoFixedRHSA-2016:015810.02.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-djangoFixedRHSA-2016:015710.02.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7python-djangoFixedRHSA-2016:012908.02.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7python-djangoFixedRHSA-2016:015610.02.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7python-djangoFixedRHSA-2016:036008.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1283553python-django: Information leak through date template filter

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

nvd
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

debian
больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x bef ...

CVSS3: 2.8
github
около 3 лет назад

Django settings leak in date template filter

4.3 Medium

CVSS2