Back

MEDIUM

Django: Data leakage via admin history log

Published May 2, 2013

Description

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published May 2, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

Severity Moderate
Public date Feb 19, 2013
Bugzilla 913041

ENISA EUVD

Assigner redhat
Published May 2, 2013
Updated Aug 6, 2024