PT-2020-5484 · Django+3 · Django+3
Published
2020-06-03
·
Updated
2026-01-03
·
CVE-2020-13254
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Django versions 2.2 before 2.2.13
Django versions 3.0 before 3.0.7
Description
The issue is related to errors in the certificate authentication procedure in the Django library. It may allow a remote attacker to gain unauthorized access to protected information. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
Recommendations
For Django versions 2.2 before 2.2.13, update to version 2.2.13 or later to resolve the issue.
For Django versions 3.0 before 3.0.7, update to version 3.0.7 or later to resolve the issue.
As a temporary workaround, consider restricting access to the memcached backend to minimize the risk of exploitation.
Exploit
Fix
Improper Certificate Validation
Information Disclosure
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Django
Linuxmint
Ubuntu