Executive brief
A vulnerability in the Django administrative interface allows authenticated users to access sensitive information they should not be able to see. By using specific search queries, an attacker can trick the system into revealing data like user passwords through a series of trial-and-error requests. This could lead to unauthorized access to other accounts or sensitive administrative data.
Technical details
The vulnerability exists in the 'django.contrib.admin' component due to improper validation of query string parameters used for object filtering. An authenticated remote attacker can bypass intended access controls by appending specialized parameters (e.g., using '__regex' or '__contains' filters) to administrative URLs. By observing the presence or absence of results in the admin interface across multiple requests, an attacker can perform a side-channel attack to reconstruct sensitive fields, such as password hashes or other private model data. This issue is addressed in Django versions 1.1.3 and 1.2.4.
Affected products
- Django Django < 1.1.3, >= 1.2, < 1.2.4, 1.3.x < 1.3 beta 1
Timeline
- 2010-12-22: disclosed: Initial security advisory by Django project
- 2011-01-10: advisory: NVD publication date
- 2018-07-23: advisory: GitHub Advisory Database publication