Lucene search

K
archlinuxArch LinuxASA-201512-3
HistoryDec 05, 2015 - 12:00 a.m.

python-django, python2-django: information leakage

2015-12-0500:00:00
Arch Linux
lists.archlinux.org
14

0.007 Low

EPSS

Percentile

80.8%

If an application allows users to specify an unvalidated format for
dates and passes this format to the date filter, e.g. {{
last_updated|date:user_date_format }}, then a malicious user could
obtain any secret in the application’s settings by specifying a settings
key instead of a date format. e.g. "SECRET_KEY" instead of "j/m/Y".

To remedy this, the underlying function used by the date template
filter, django.utils.formats.get_format(), now only allows accessing the
date/time formatting settings.

OSVersionArchitecturePackageVersionFilename
anyanyanypython2-django< 1.8.7-1UNKNOWN
anyanyanypython-django< 1.8.7-1UNKNOWN