MEDIUM
Django: Data leakage via admin history log
Published May 2, 2013
5.3
MEDIUMCVSS 4.0
EPSS 1.82%
Description
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Affected products
No data.
Configuration 1
OR
- 1.3
- 1.3
- 1.3
- 1.3.1
- 1.3.2
- 1.3.3
Configuration 2
OR
- 1.4
- 1.4
- 1.4
- 1.4.1
- 1.4.2
Configuration 3
OR
- 1.5
- 1.5
Configuration 4
OR
- 10.04
- 11.10
- 12.04
- 12.10
No data.
OpenStack Folsom for RHEL 6
Django14-0:1.4.4-1.el6ost
Fixed · RHSA-2013:0670
Red Hat Subscription Asset Manager
Django
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack Folsom for RHEL 6 | Django14-0:1.4.4-1.el6ost | Fixed | RHSA-2013:0670 |
| Red Hat Subscription Asset Manager | Django | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (13)
- http://rhn.redhat.com/errata/RHSA-2013-0670.html vendor-advisoryx_refsource_REDHAT
- http://ubuntu.com/usn/usn-1757-1 vendor-advisoryx_refsource_UBUNTU
- http://www.debian.org/security/2013/dsa-2634 vendor-advisoryx_refsource_DEBIAN
- https://access.redhat.com/security/cve/CVE-2013-0305 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=913041 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0004 Advisory
- https://github.com/advisories/GHSA-r7w6-p47g-vj53 Advisory
- https://github.com/django/django/commit/0e7861aec73702f7933ce2a93056f7983939f0d6
- https://github.com/django/django/commit/d3a45e10c8ac8268899999129daa27652ec0da35
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2013-16.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2013-0305
- https://www.cve.org/CVERecord?id=CVE-2013-0305
- https://www.djangoproject.com/weblog/2013/feb/19/security x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2013-0670.html | vendor-advisoryx_refsource_REDHAT | |
| http://ubuntu.com/usn/usn-1757-1 | vendor-advisoryx_refsource_UBUNTU | |
| http://www.debian.org/security/2013/dsa-2634 | vendor-advisoryx_refsource_DEBIAN | |
| https://access.redhat.com/security/cve/CVE-2013-0305 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=913041 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0004 | Advisory | |
| https://github.com/advisories/GHSA-r7w6-p47g-vj53 | Advisory | |
| https://github.com/django/django/commit/0e7861aec73702f7933ce2a93056f7983939f0d6 | ||
| https://github.com/django/django/commit/d3a45e10c8ac8268899999129daa27652ec0da35 | ||
| https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2013-16.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2013-0305 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-0305 | ||
| https://www.djangoproject.com/weblog/2013/feb/19/security | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 2, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
Link CVE-2013-0305
CISA Vulnrichment
No data
GitHub
Link GHSA-R7W6-P47G-VJ53