CVE-2010-4534
Summary
The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.
Impact & exploitability
AV:N/AC:L/Au:S/C:P/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://code.djangoproject.com/changeset/15031 ↗
Additional information
- NVD record
- http://code.djangoproject.com/changeset/15031Patch
- http://secunia.com/advisories/42715Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053041.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053072.html
- http://secunia.com/advisories/42827
- http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0580.htmlExploit
- http://evilpacket.net/2010/dec/22/information-leakage-django-administrative-interfac/Exploit
- http://ngenuity-is.com/advisories/2010/dec/22/information-leakage-in-django-administrative-inter/Exploit