VDB
BDU%3A2024-07168
BDU%3A2024-07168
PUBLISHED
CVSS 5 MEDIUM
Уязвимость метода django.contrib.auth.backends.ModelBackend.authenticate() программной платформы для веб-приложений Django, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Django Software Foundation | Django |
Timeline
- Sep 18, 2024 CVE Published
References
- https://docs.djangoproject.com/en/dev/releases/security/ url
- https://github.com/advisories/GHSA-x7q2-wr7g-xqmf url
- https://groups.google.com/forum/#%21forum/django-announce url
- https://vuldb.com/?id.271007 url
- https://github.com/django/django/commit/07cefdee4a9d1fcd9a3a631cbd07c78defd1923b url
- https://www.djangoproject.com/weblog/2024/jul/09/security-releases/ advisory
- https://github.com/django/django/releases/tag/5.0.7 advisory
- https://github.com/django/django/releases/tag/4.2.14 advisory
- https://github.com/django/django/commit/156d3186c96e3ec2ca73b8b25dc2ef366e38df14 advisory