Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9013

Опубликовано: 09 дек. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

РелизСтатусПримечание
devel

released

1.8.7-1ubuntu9
esm-infra-legacy/trusty

not-affected

1.6.1-2ubuntu0.16
esm-infra/xenial

not-affected

1.8.7-1ubuntu5.4
precise

released

1.3.1-4ubuntu1.22
trusty

released

1.6.1-2ubuntu0.16
trusty/esm

not-affected

1.6.1-2ubuntu0.16
upstream

released

1.10.3,1.9.11,1.8.16
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

released

1.8.7-1ubuntu5.4

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

CVSS3: 9.8
nvd
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

CVSS3: 9.8
debian
больше 8 лет назад

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.1 ...

CVSS3: 9.8
github
около 3 лет назад

Django user with hardcoded password created when running tests on Oracle

suse-cvrf
около 7 лет назад

Security update for python-Django

7.5 High

CVSS2

9.8 Critical

CVSS3