漏洞标题
错误报告中可能意外泄露的敏感信息
漏洞描述信息
错误报告中可能意外泄露敏感信息
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
Potential sensitive information disclosed in error reports
漏洞描述信息
django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires: A site is using django-registration < 3.1.2, The site has detailed error reports (such as Django's emailed error reports to site staff/developers) enabled and a server-side error (HTTP 5xx) occurs during an attempt by a user to register an account. Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password).
CVSS信息
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
漏洞类别
通过错误消息导致的信息暴露
漏洞标题
django-registration 安全漏洞
漏洞描述信息
James Bennett django-registration是James Bennett开源的一个应用程序。Django的用户注册应用程序。 django-registration 存在安全漏洞,该漏洞源于敏感数据可能会包含在错误报告中。
CVSS信息
N/A
漏洞类别
其他