PYSEC-2018-3

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2018-3.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2018-3
Aliases
Published
2018-10-02T18:29:00Z
Modified
2023-11-08T04:00:02.548230Z
Summary
[none]
Details

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

References

Affected packages

PyPI / django

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.1
Fixed
2.1.2

Affected versions

2.*

2.1
2.1.1