The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.djangoproject.com/weblog/2013/feb/19/security/ | patch vendor advisory |
http://ubuntu.com/usn/usn-1757-1 | vendor advisory |
http://www.debian.org/security/2013/dsa-2634 | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0670.html | vendor advisory |