PT-2016-1255 · Django · Django

Myk Willis

·

Publicado

2016-02-08

·

Atualizado

2022-05-17

·

CVE-2016-2048

CVSS v4.0

7.0

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions 1.9.x through 1.9.1
Description The issue allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission. This is due to incorrect settings of the save as parameter in the ModelAdmin class.
Recommendations For Django versions 1.9.x through 1.9.1, update to version 1.9.2 or later to resolve the issue. As a temporary workaround, consider setting ModelAdmin.save as to False until a patch is available.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00527
CVE-2016-2048
GHSA-46X4-9JMV-JC8P
PYSEC-2016-14

Produtos afetados

Django