PT-2020-5484 · Django+3 · Django+3

Published

2020-06-03

·

Updated

2026-01-03

·

CVE-2020-13254

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Django versions 2.2 before 2.2.13 Django versions 3.0 before 3.0.7
Description The issue is related to errors in the certificate authentication procedure in the Django library. It may allow a remote attacker to gain unauthorized access to protected information. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
Recommendations For Django versions 2.2 before 2.2.13, update to version 2.2.13 or later to resolve the issue. For Django versions 3.0 before 3.0.7, update to version 3.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the memcached backend to minimize the risk of exploitation.

Exploit

Fix

Improper Certificate Validation

Information Disclosure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3491
BDU:2021-00780
BIT-DJANGO-2020-13254
CVE-2020-13254
DLA-2233-1
DLA-2233-2
DSA-4705-1
GHSA-WPJR-J57X-WXFW
OPENSUSE-SU-2024:11205-1
OPENSUSE-SU-2024:13887-1
OPENSUSE-SU-2024:14208-1
OPENSUSE-SU-2026:10005-1
PYSEC-2020-31
RHSA-2021:0915
RHSA-2021:0933
SUSE-RU-2020:2072-1
SUSE-RU-2020:2161-1
SUSE-SU-2020:1901-1
USN-4381-1
USN-4381-2

Affected Products

Alt Linux
Django
Linuxmint
Ubuntu