Описание
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 2 | python-django | Not affected | ||
Red Hat Certification for Red Hat Enterprise Linux 7 | python-django | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-django | Not affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | python-django | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | python-django | Not affected | ||
Red Hat OpenStack Platform 12 (Pike) | python-django | Not affected | ||
Red Hat OpenStack Platform 13 (Queens) | python-django | Not affected | ||
Red Hat OpenStack Platform 14 (Rocky) | python-django | Not affected | ||
Red Hat OpenStack Platform 8 (Liberty) | python-django | Not affected | ||
Red Hat OpenStack Platform 8 (Liberty) Operational Tools | python-django | Not affected |
Показывать по
Дополнительная информация
Статус:
2.7 Low
CVSS3
Связанные уязвимости
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
An issue was discovered in Django 2.1 before 2.1.2, in which unprivile ...
Django allows unprivileged users to read the password hashes of arbitrary accounts
2.7 Low
CVSS3