QID 981096
QID 981096: Python (pip) Security Update for django (GHSA-fwr5-q9rx-294f)
The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fwr5-q9rx-294f for updates pertaining to this vulnerability.
Vendor References
- GHSA-fwr5-q9rx-294f -
github.com/advisories/GHSA-fwr5-q9rx-294f
CVEs related to QID 981096
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fwr5-q9rx-294f | django |
|