QID 981253
QID 981253: Python (pip) Security Update for django (GHSA-6mx3-3vqg-hpp2)
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6mx3-3vqg-hpp2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6mx3-3vqg-hpp2 -
github.com/advisories/GHSA-6mx3-3vqg-hpp2
CVEs related to QID 981253
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6mx3-3vqg-hpp2 | django |
|