CVE-2013-0305: Infoleak
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0305?
CVE-2013-0305 has a high severity rating due to its potential to expose sensitive object history information to unauthorized users.
How do I fix CVE-2013-0305?
To fix CVE-2013-0305, update Django to version 1.3.6 or higher for the 1.3.x series, or to 1.4.4 or higher for the 1.4.x series.
Which Django versions are affected by CVE-2013-0305?
Django versions 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 are affected by CVE-2013-0305.
What type of attack does CVE-2013-0305 allow?
CVE-2013-0305 allows remote authenticated administrators to access sensitive object history information without proper permission checks.
Is CVE-2013-0305 specific to any operating systems?
CVE-2013-0305 affects Django installations across multiple operating systems that use the vulnerable Django versions.