QID 997698
Date Published: 2024-03-13
QID 997698: Python (Pip) Security Update for django (GHSA-6wcr-wcqm-3mfh)
The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6wcr-wcqm-3mfh for updates and patch information.
Vendor References
- GHSA-6wcr-wcqm-3mfh -
github.com/advisories/GHSA-6wcr-wcqm-3mfh
CVEs related to QID 997698
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6wcr-wcqm-3mfh | django |
|