PYSEC-2013-16

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2013-16.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2013-16
Aliases
Published
2013-05-02T14:55:00Z
Modified
2023-11-01T05:30:31.724036Z
Summary
[none]
Details

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.3
Fixed
1.3.6
Introduced
1.4
Fixed
1.4.4

Affected versions

1.*

1.3
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4
1.4.1
1.4.2
1.4.3