Description
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9Complexity: Low
Integrity: None
Availability: None
Affected Packages2 packages
Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10
🔴Vulnerability Details
4OSVDjango Data leakage via admin history log↗2022-05-05 ▶ GHSADjango Data leakage via admin history log↗2022-05-05 ▶ OSVCVE-2013-0305: The administrative interface for Django 1↗2013-05-02 ▶ CVEListCVE-2013-0305: The administrative interface for Django 1↗2013-05-02 ▶ 📋Vendor Advisories
3UbuntuDjango vulnerabilities↗2013-03-07 ▶ Red HatDjango: Data leakage via admin history log↗2013-02-19 ▶ DebianCVE-2013-0305: python-django - The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, ...↗2013 ▶ 💬Community
5BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [epel-5]↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django14 various flaws [epel-6]↗2013-02-20 ▶ BugzillaCVE-2013-0305 Django: Data leakage via admin history log↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [fedora-17]↗2013-02-20 ▶ BugzillaCVE-2013-0305 CVE-2013-0306 Django various flaws [epel-6]↗2013-02-20 ▶