SB2016020101 - Security restrictions bypass in Django



SB2016020101 - Security restrictions bypass in Django

Published: February 1, 2016

Security Bulletin ID SB2016020101
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2016-2048)

The vulnerability allows a remote authenticated attacker to write arbitrary files on the target system.

The weakness exists due to improper access restrictions. A remote attacker can bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

Remediation

Install update from vendor's website.