4

CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Djangoproject ≫ Django Version 1.3
Djangoproject ≫ Django Version 1.3 Update alpha1
Djangoproject ≫ Django Version 1.3 Update beta1
Djangoproject ≫ Django Version 1.3.1
Djangoproject ≫ Django Version 1.3.2
Djangoproject ≫ Django Version 1.3.3
Djangoproject ≫ Django Version 1.4
Djangoproject ≫ Django Version 1.4 Update alpha
Djangoproject ≫ Django Version 1.4 Update beta
Djangoproject ≫ Django Version 1.4.1
Djangoproject ≫ Django Version 1.4.2
Djangoproject ≫ Django Version 1.5 Update alpha
Djangoproject ≫ Django Version 1.5 Update beta
Canonical ≫ Ubuntu Linux Version 10.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.82% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://ubuntu.com/usn/usn-1757-1
http://www.debian.org/security/2013/dsa-2634
http://rhn.redhat.com/errata/RHSA-2013-0670.html
https://www.djangoproject.com/weblog/2013/feb/19/security/
Patch
Vendor Advisory