Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9013

Опубликовано: 01 нояб. 2016
Источник: redhat
CVSS3: 7.4
CVSS2: 4

Описание

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3DjangoNot affected
Red Hat Ceph Storage 2python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-djangoNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Toolspython-djangoNot affected
Red Hat OpenStack Platform 10 (Newton)python-djangoNot affected
Red Hat OpenStack Platform 10 (Newton) Operational Toolspython-djangoNot affected
Red Hat OpenStack Platform 8 (Liberty)python-djangoNot affected
Red Hat OpenStack Platform 8 (Liberty) Operational Toolspython-djangoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-798
https://bugzilla.redhat.com/show_bug.cgi?id=1389414python-django: user with hardcoded password created when running tests on Oracle

7.4 High

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

CVSS3: 9.8
nvd
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

CVSS3: 9.8
debian
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.1 ...

CVSS3: 9.8
github
около 3 лет назад

Django user with hardcoded password created when running tests on Oracle

suse-cvrf
около 7 лет назад

Security update for python-Django

7.4 High

CVSS3

4 Medium

CVSS2