5

CVE-2013-4315

Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Djangoproject ≫ Django Version 1.4
Djangoproject ≫ Django Version 1.4.1
Djangoproject ≫ Django Version 1.4.2
Djangoproject ≫ Django Version 1.4.4
Djangoproject ≫ Django Version 1.4.5
Djangoproject ≫ Django Version 1.4.6
Djangoproject ≫ Django Version 1.5
Djangoproject ≫ Django Version 1.5 Update alpha
Djangoproject ≫ Django Version 1.5 Update beta
Djangoproject ≫ Django Version 1.5.1
Djangoproject ≫ Django Version 1.6 Update beta1
Djangoproject ≫ Django Version 1.6 Update beta2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.21% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://lists.opensuse.org/opensuse-updates/2013-10/msg00015.html
http://rhn.redhat.com/errata/RHSA-2013-1521.html
http://secunia.com/advisories/54772
Vendor Advisory
http://secunia.com/advisories/54828
Vendor Advisory
http://www.debian.org/security/2013/dsa-2755
https://www.djangoproject.com/weblog/2013/sep/10/security-releases-issued/
Patch
Vendor Advisory