Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0305

Опубликовано: 02 мая 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4

Описание

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

РелизСтатусПримечание
devel

not-affected

1.4.5-1
hardy

ignored

end of life
lucid

released

1.1.1-2ubuntu1.8
oneiric

released

1.3-2ubuntu1.6
precise

released

1.3.1-4ubuntu1.6
quantal

released

1.4.1-2ubuntu0.3
upstream

released

1.4.4-1

Показывать по

EPSS

Процентиль: 44%
0.00209
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

nvd
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

debian
около 12 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x befo ...

CVSS3: 4.3
github
около 3 лет назад

Django Data leakage via admin history log

EPSS

Процентиль: 44%
0.00209
Низкий

4 Medium

CVSS2