CVE-2010-4534Improper Input Validation in Django

Severity
4.0MEDIUMNVD
EPSS
0.6%
top 31.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 10
Latest updateJul 23

Description

The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

PyPIdjangoproject/django1.21.2.4+1
NVDdjangoproject/django1.1.2+14

Patches

🔴Vulnerability Details

4
GHSA
Improper query string handling in Django2018-07-23
OSV
Improper query string handling in Django2018-07-23
CVEList
CVE-2010-4534: The administrative interface in django2011-01-10
OSV
CVE-2010-4534: The administrative interface in django2011-01-10

📋Vendor Advisories

2
Ubuntu
Django vulnerabilities2011-01-07
Debian
CVE-2010-4534: python-django - The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2...2010

💬Community

1
Bugzilla
CVE-2010-4534, CVE-2010-4535 Information leakage and DoS vulnerabilities in Django < 1.2.4 & 1.1.32010-12-23
CVE-2010-4534 — Improper Input Validation in Django | cvebase