Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7560
HistoryOct 03, 2018 - 3:07 a.m.

Information Disclosure

2018-10-0303:07:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.002 Low

EPSS

Percentile

52.3%

django is vulnerable to information disclosure. Admin users with the view-only permission are able to retrieve the entire password hash of arbitrary accounts through the read-only password widget that displays obfuscated password hashes.

CPENameOperatorVersion
djangole2.1.1
djangole1.11.26