Description
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2634-1 | python-django security update |
EUVD |
EUVD-2013-0004 | The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information. |
Github GHSA |
GHSA-r7w6-p47g-vj53 | Django Data leakage via admin history log |
Ubuntu USN |
USN-1757-1 | Django vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T14:18:09.639Z
Reserved: 2012-12-06T00:00:00.000Z
Link: CVE-2013-0305
No data.
Status : Deferred
Published: 2013-05-02T14:55:05.257
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-0305
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA
Ubuntu USN