First published: Mon Feb 14 2011(Updated: )
Directory traversal vulnerability in Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows might allow remote attackers to read or execute files via a / (slash) character in a key in a session cookie, related to session replays.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Djangoproject Django | =1.1 | |
Djangoproject Django | =1.1.0 | |
Djangoproject Django | =1.1.2 | |
Djangoproject Django | =1.1.3 | |
Microsoft Windows | ||
Djangoproject Django | =1.2 | |
Djangoproject Django | =1.2.1 | |
Djangoproject Django | =1.2.2 | |
Djangoproject Django | =1.2.3 | |
Djangoproject Django | =1.2.4 | |
All of | ||
Any of | ||
Djangoproject Django | =1.1 | |
Djangoproject Django | =1.1.0 | |
Djangoproject Django | =1.1.2 | |
Djangoproject Django | =1.1.3 | |
Microsoft Windows | ||
All of | ||
Any of | ||
Djangoproject Django | =1.2 | |
Djangoproject Django | =1.2.1 | |
Djangoproject Django | =1.2.2 | |
Djangoproject Django | =1.2.3 | |
Djangoproject Django | =1.2.4 | |
Microsoft Windows | ||
pip/Django | >=1.2<1.2.5 | 1.2.5 |
pip/Django | >=1.1<1.1.4 | 1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0698 is rated as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2011-0698, upgrade to Django version 1.1.4 or 1.2.5 or later.
CVE-2011-0698 affects Django versions 1.1.x before 1.1.4 and 1.2.x before 1.2.5 on Windows.
No, if you are using Django 1.2.5 or later, you are not vulnerable to CVE-2011-0698.
CVE-2011-0698 could allow remote attackers to read or execute files by exploiting a directory traversal vulnerability.