CVE-2010-4534
Django <1.1.3, 1.2.x<1.2.4, 1.3.x<1.3b1 Authenticated Info Disclosure via Admin Interface
Title source: llmDescription
The administrative interface in django.contrib.admin in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not properly restrict use of the query string to perform certain object filtering, which allows remote authenticated users to obtain sensitive information via a series of requests containing regular expressions, as demonstrated by a created_by__password__regex parameter.
References (18)
Core 18
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/45562
Exploit x_refsource_misc
http://ngenuity-is.com/advisories/2010/dec/22/information-leakage-in-django-administrative-inter/
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2010/12/23/4
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/515446
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1040-1
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/01/03/5
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42913
Exploit x_refsource_misc
http://evilpacket.net/2010/dec/22/information-leakage-django-administrative-interfac/
Patch x_refsource_confirm
http://code.djangoproject.com/changeset/15031
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0048
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0098
Patch, Vendor Advisory x_refsource_confirm
http://www.djangoproject.com/weblog/2010/dec/22/security/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053041.html
Patch x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=665373
Exploit mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2010-12/0580.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42715
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/053072.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42827
Scores
EPSS
0.0170
EPSS Percentile
74.8%
Details
CWE
CWE-264
Status
published
Products (17)
djangoproject/django
0.91
djangoproject/django
0.95
djangoproject/django
0.95.1
djangoproject/django
0.96
djangoproject/django
1.0
djangoproject/django
1.0.1
djangoproject/django
1.0.2
djangoproject/django
1.1
djangoproject/django
1.1.0
djangoproject/django
1.2
... and 7 more
Published
Jan 10, 2011
Tracked Since
Feb 18, 2026