QID 995374
Date Published: 2023-09-25
QID 995374: Python (Pip) Security Update for django (GHSA-r5cj-wv24-92p5)
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r5cj-wv24-92p5 for updates and patch information.
Vendor References
- GHSA-r5cj-wv24-92p5 -
github.com/advisories/GHSA-r5cj-wv24-92p5
CVEs related to QID 995374
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r5cj-wv24-92p5 | django |
|