Search 187964 CVE descriptions
and 85075 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Debian Local Security Checks
Title:Debian LTS: Security Advisory for python-django (DLA-2233-1)
Summary:The remote host is missing an update for the 'python-django'; package(s) announced via the DLA-2233-1 advisory.
The remote host is missing an update for the 'python-django'
package(s) announced via the DLA-2233-1 advisory.

Vulnerability Insight:
It was discovered that there were two issues in Django, the Python
web development framework:

* CVE-2020-13254: Potential a data leakage via malformed memcached

In cases where a memcached backend does not perform key validation,
passing malformed cache keys could result in a key collision, and
potential data leakage. In order to avoid this vulnerability, key
validation is added to the memcached cache backends.

* CVE-2020-13596: Possible XSS via admin ForeignKeyRawIdWidget.

Query parameters to the admin ForeignKeyRawIdWidget were not
properly URL encoded, posing an XSS attack vector.
ForeignKeyRawIdWidget now ensures query parameters are correctly
URL encoded.

For more information, please see:

This upload also addresses test failures introduced in
1.7.11-1+deb8u3 and 1.7.11-1+deb8u8 via the fixes for CVE-2018-7537
and CVE-2019-19844 respectfully.

Affected Software/OS:
'python-django' package(s) on Debian Linux.

For Debian 8 'Jessie', this issue has been fixed in python-django version

We recommend that you upgrade your python-django packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-7537
BugTraq ID: 103357
Debian Security Information: DSA-4161 (Google Search)
RedHat Security Advisories: RHSA-2018:2927
RedHat Security Advisories: RHSA-2019:0265
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 85075 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2020 E-Soft Inc. All rights reserved.