Information disclosure in Django - CVE-2016-9013
Published: November 2, 2016 / Updated: November 2, 2016
Vulnerability identifier: #VU1130
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9013
CWE-ID: CWE-259
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to obtain potentially sensitive information on the target system.
The weakness exists due to use of hardcoded password that allows a remote attacker to connect to the database server.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive information.
The weakness exists due to use of hardcoded password that allows a remote attacker to connect to the database server.
Successful exploitation of the vulnerability results in disclosure of potentially sensitive information.
Affected software
Django
Arch Linux
Fedora
Ubuntu
py-django (Alpine package)
python-django
Arch Linux
Fedora
Ubuntu
py-django (Alpine package)
python-django
How to mitigate CVE-2016-9013
Update to 1.8.16, 1.9.11, 1.10.3.
py-django (Alpine package) - update to 1.8.16-r0
python-django - addressed in versions 1.6.11.6-1.el7, 1.9.11-1.fc24, 1.9.11-1.fc25
python-django - addressed in versions 1.6.11.6-1.el7, 1.9.11-1.fc24, 1.9.11-1.fc25
External References
Related Security Bulletins
- Ubuntu update for Django
- Arch Linux update for python-django
- Arch Linux update for python2-django
- Arch Linux update for python-django
- Arch Linux update for python2-django
- Information disclosure in py-django (Alpine package)
- Fedora 25 update for python-django
- Fedora 24 update for python-django
- Fedora EPEL 7 update for python-django