CVE-2014-0483
Publication date 26 August 2014
Last updated 24 July 2024
Ubuntu priority
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-django | 14.04 LTS trusty |
Fixed 1.6.1-2ubuntu0.4
|
Patch details
Package | Patch details |
---|---|
python-django |
References
Related Ubuntu Security Notices (USN)
- USN-2347-1
- Django vulnerabilities
- 16 September 2014