CVE-2014-0483
Published: 26 August 2014
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.
Priority
Status
Package | Release | Status |
---|---|---|
python-django Launchpad, Ubuntu, Debian |
lucid |
Released
(1.1.1-2ubuntu1.13)
|
precise |
Released
(1.3.1-4ubuntu1.12)
|
|
trusty |
Released
(1.6.1-2ubuntu0.4)
|
|
upstream |
Released
(1.6.6-1)
|
|
Patches: upstream: https://github.com/django/django/commit/027bd348642007617518379f8b02546abacaa6e0 upstream: https://github.com/django/django/commit/4685026840f0e2b895f980b6a33ad1b282aa7852 upstream: https://github.com/django/django/commit/065caafa70b6c422f73e364a4c241b6538969d7b upstream: https://github.com/django/django/commit/f7c494f2506250b8cb5923714360a3642ed63e0f upstream: https://github.com/django/django/commit/e3453b61c6269d7868ceb404abaea5ad2569778f upstream: https://github.com/django/django/commit/a7af6ad96a35634383c2d73fa049127e85a886a6 |