Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
Vulnerability Description
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses like the ModelSelect2MultipleWidget and ModelSelect2Widget can leak secret access tokens across requests. This can allow users to access restricted query sets and restricted data. This issue has been patched in version 8.4.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
将私有的资源传输到一个新的空间(资源泄露)
Vulnerability Title
django-select2 安全漏洞
Vulnerability Description
django-select2是Johannes Maron个人开发者的一个Select2的Django集成。 django-select2 8.4.1之前版本存在安全漏洞,该漏洞源于HeavySelect2Mixin子类可能泄露访问令牌。
CVSS Information
N/A
Vulnerability Type
N/A