CVE-2013-0305
MEDIUM severity · CVSS 4 · Information disclosure
4CVSS MEDIUM
Summary
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)2%
AV:N/AC:L/Au:S/C:P/I:N/A:N
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://www.djangoproject.com/weblog/2013/feb/19/security/ ↗