CVE-2019-19118 - log back

CVE-2019-19118 edited at 03 Dec 2019 13:23:40
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Privilege escalation
Description
+ A privilege escalation issue has been found in Django since 2.1 and before 2.2.8 or 2.1.15, where a user who lacks permission to edit a model should not be able to trigger its save-related signals.
References
+ https://www.djangoproject.com/weblog/2019/dec/02/security-releases/
+ https://github.com/django/django/commit/36f580a17f0b3cb087deadf3b65eea024f479c21
Notes
CVE-2019-19118 created at 03 Dec 2019 13:20:21