CVE-2019-19118 log
Source |
|
Severity | Low |
Remote | Yes |
Type | Privilege escalation |
Description | A privilege escalation issue has been found in Django since 2.1 and before 2.2.8 or 2.1.15, where a user who lacks permission to edit a model should not be able to trigger its save-related signals. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1070 | python-django | 2.2.6-2 | 2.2.9-1 | Low | Fixed |
References |
---|
https://www.djangoproject.com/weblog/2019/dec/02/security-releases/ https://github.com/django/django/commit/36f580a17f0b3cb087deadf3b65eea024f479c21 |