[WID-SEC-2023-1137] Django: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen CVSS Base Score 7.3 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 03.05.2023 Stand UPDATE 13.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Django ist ein in Python geschriebenes serverseitiges Web-Framework, das einem Model-View-Presenter-Schema folgt. Produkte UPDATE 04.01.2026 SUSE openSUSE UPDATE 09.08.2023 Red Hat Enterprise Linux UPDATE 16.07.2023 SUSE Linux UPDATE 24.05.2023 Ubuntu Linux UPDATE 10.05.2023 Fedora Linux UPDATE 07.05.2023 Debian Linux 03.05.2023 Ubuntu Linux 18.04 Ubuntu Linux 22.04 Open Source Django <4.2.1 Open Source Django <4.1.9 Open Source Django <3.2.19 Ubuntu Linux 23.04 Ubuntu Linux 22.10 Ubuntu Linux 20.04 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Django ausnutzen, um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A remote, anonymous attacker can exploit a vulnerability in Django to bypass security protections, with a CVSS base score of 7.3 (High). Affected versions include Django versions prior to 4.2.1, 4.1.9, and 3.2.19. Mitigations are available, and major Linux distributions have released updates.