Release date:
Updated on:
Affected Systems:
Django 1.6.x
Django 1.5.x
Django 1.4.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0472
Django is an open-source Web application framework driven by Python programming language.
Django versions earlier than 1.4.11, 1.5.6, 1.6.3, 1.7 beta 2 are available in django. core. urlresolvers. A security vulnerability exists in the implementation of the reverse function. Remote attackers can import and execute arbitrary Python modules by using user input and adding Python paths.
Recommended reading:
Install Nginx + uWSGI + Django on Ubuntu Server 12.04
Django tutorial
Build a Django Python MySQL Linux development environment
<* Source: Benjamin Bach
Link: http://secunia.com/advisories/58201/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Django
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.djangoproject.com/
Https://www.djangoproject.com/weblog/2014/apr/21/security/
Django details: click here
Django's: click here