Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.892233
Category:Debian Local Security Checks
Title:Debian LTS: Security Advisory for python-django (DLA-2233-1)
Summary:The remote host is missing an update for the 'python-django'; package(s) announced via the DLA-2233-1 advisory.
Description:Summary:
The remote host is missing an update for the 'python-django'
package(s) announced via the DLA-2233-1 advisory.

Vulnerability Insight:
It was discovered that there were two issues in Django, the Python
web development framework:

* CVE-2020-13254: Potential a data leakage via malformed memcached
keys.

In cases where a memcached backend does not perform key validation,
passing malformed cache keys could result in a key collision, and
potential data leakage. In order to avoid this vulnerability, key
validation is added to the memcached cache backends.

* CVE-2020-13596: Possible XSS via admin ForeignKeyRawIdWidget.

Query parameters to the admin ForeignKeyRawIdWidget were not
properly URL encoded, posing an XSS attack vector.
ForeignKeyRawIdWidget now ensures query parameters are correctly
URL encoded.

For more information, please see:

This upload also addresses test failures introduced in
1.7.11-1+deb8u3 and 1.7.11-1+deb8u8 via the fixes for CVE-2018-7537
and CVE-2019-19844 respectfully.

Affected Software/OS:
'python-django' package(s) on Debian Linux.

Solution:
For Debian 8 'Jessie', this issue has been fixed in python-django version
1.7.11-1+deb8u9.

We recommend that you upgrade your python-django packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-7537
BugTraq ID: 103357
http://www.securityfocus.com/bid/103357
Debian Security Information: DSA-4161 (Google Search)
https://www.debian.org/security/2018/dsa-4161
https://lists.debian.org/debian-lts-announce/2018/03/msg00006.html
RedHat Security Advisories: RHSA-2018:2927
https://access.redhat.com/errata/RHSA-2018:2927
RedHat Security Advisories: RHSA-2019:0265
https://access.redhat.com/errata/RHSA-2019:0265
https://usn.ubuntu.com/3591-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.