4

CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

Data is provided by the National Vulnerability Database (NVD)
DjangoprojectDjango Version1.3
DjangoprojectDjango Version1.3 Updatealpha1
DjangoprojectDjango Version1.3 Updatebeta1
DjangoprojectDjango Version1.3.1
DjangoprojectDjango Version1.3.2
DjangoprojectDjango Version1.3.3
DjangoprojectDjango Version1.4
DjangoprojectDjango Version1.4 Updatealpha
DjangoprojectDjango Version1.4 Updatebeta
DjangoprojectDjango Version1.4.1
DjangoprojectDjango Version1.4.2
DjangoprojectDjango Version1.5 Updatealpha
DjangoprojectDjango Version1.5 Updatebeta
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.21% 0.404
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.