Описание
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged POST data in GenericInlineModelAdmin. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 3:5.2.9-0ubuntu4 |
| esm-infra-legacy/trusty | ignored | changes too intrusive |
| esm-infra-legacy/xenial | released | 1.8.7-1ubuntu5.15+esm12 |
| esm-infra/bionic | released | 1:1.11.11-1ubuntu1.21+esm15 |
| esm-infra/focal | released | 2:2.2.12-1ubuntu0.29+esm8 |
| esm-infra/xenial | released | 1.8.7-1ubuntu5.15+esm12 |
| jammy | released | 2:3.2.12-2ubuntu1.26 |
| noble | released | 3:4.2.11-1ubuntu1.15 |
| questing | released | 3:5.2.4-1ubuntu2.4 |
| upstream | released | 5.2.13,4.2.30 |
Показывать по
9.8 Critical
CVSS3
Связанные уязвимости
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank N05ec@LZU-DSLab for reporting this issue.
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4. ...
Django vulnerable to privilege abuse in GenericInlineModelAdmin
Уязвимость класса GenericInlineModelAdmin фреймворка для веб-разработки Django, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
9.8 Critical
CVSS3