CVE-2013-0305Sensitive Information Exposure in Django

Severity
4.0MEDIUMNVD
EPSS
0.2%
top 52.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 5

Description

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

PyPIdjangoproject/django1.31.3.6+1
NVDdjangoproject/django8 versions+7

Also affects: Ubuntu Linux 10.04, 11.10, 12.04, 12.10

Patches

🔴Vulnerability Details

4
OSV
Django Data leakage via admin history log2022-05-05
GHSA
Django Data leakage via admin history log2022-05-05
OSV
CVE-2013-0305: The administrative interface for Django 12013-05-02
CVEList
CVE-2013-0305: The administrative interface for Django 12013-05-02

📋Vendor Advisories

3
Ubuntu
Django vulnerabilities2013-03-07
Red Hat
Django: Data leakage via admin history log2013-02-19
Debian
CVE-2013-0305: python-django - The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, ...2013

💬Community

5
Bugzilla
CVE-2013-0305 CVE-2013-0306 Django various flaws [epel-5]2013-02-20
Bugzilla
CVE-2013-0305 CVE-2013-0306 Django14 various flaws [epel-6]2013-02-20
Bugzilla
CVE-2013-0305 Django: Data leakage via admin history log2013-02-20
Bugzilla
CVE-2013-0305 CVE-2013-0306 Django various flaws [fedora-17]2013-02-20
Bugzilla
CVE-2013-0305 CVE-2013-0306 Django various flaws [epel-6]2013-02-20
CVE-2013-0305 — Sensitive Information Exposure | cvebase