漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Potential sensitive information disclosed in error reports
Vulnerability Description
django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data, with the result that sensitive data could be included in error reports rather than removed automatically by Django. Triggering this requires: A site is using django-registration < 3.1.2, The site has detailed error reports (such as Django's emailed error reports to site staff/developers) enabled and a server-side error (HTTP 5xx) occurs during an attempt by a user to register an account. Under these conditions, recipients of the detailed error report will see all submitted data from the account-registration attempt, which may include the user's proposed credentials (such as a password).
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
django-registration 安全漏洞
Vulnerability Description
James Bennett django-registration是James Bennett开源的一个应用程序。Django的用户注册应用程序。 django-registration 存在安全漏洞,该漏洞源于敏感数据可能会包含在错误报告中。
CVSS Information
N/A
Vulnerability Type
N/A