5

CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Djangoproject ≫ Django Version <= 1.7.10
Djangoproject ≫ Django Version 1.8.0
Djangoproject ≫ Django Version 1.8.1
Djangoproject ≫ Django Version 1.8.2
Djangoproject ≫ Django Version 1.8.3
Djangoproject ≫ Django Version 1.8.4
Djangoproject ≫ Django Version 1.8.5
Djangoproject ≫ Django Version 1.8.6
Djangoproject ≫ Django Version 1.9.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.28% 0.898
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173375.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174770.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00014.html
http://lists.opensuse.org/opensuse-updates/2015-12/msg00017.html
http://rhn.redhat.com/errata/RHSA-2016-0129.html
http://rhn.redhat.com/errata/RHSA-2016-0156.html
http://rhn.redhat.com/errata/RHSA-2016-0157.html
http://rhn.redhat.com/errata/RHSA-2016-0158.html
http://www.debian.org/security/2015/dsa-3404
http://www.securityfocus.com/bid/77750
http://www.securitytracker.com/id/1034237
http://www.ubuntu.com/usn/USN-2816-1
https://github.com/django/django/commit/316bc3fc9437c5960c24baceb93c73f1939711e4
https://www.djangoproject.com/weblog/2015/nov/24/security-releases-issued/
Patch
Vendor Advisory