The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py-django | Aug 30, 2017 | Dec 7, 2015 |
| Debian | — | Upgrade python-django | Dec 7, 2015 | Nov 25, 2015 |
| Freebsd | — | Upgrade py34-django18Upgrade py33-django-develUpgrade py34-djangoUpgrade py32-django17Upgrade py27-django18Upgrade py33-django17Upgrade py27-django-develUpgrade py32-djangoUpgrade py32-django-develUpgrade py27-djangoUpgrade py27-django17Upgrade py33-django18Upgrade py33-djangoUpgrade py34-django17Upgrade py32-django18Upgrade py34-django-devel | Dec 10, 2025 | Nov 30, 2015 |
| Oracle Solaris | — | Upgrade cloud/openstack/horizon to version 0.2015.1.2-0.175.3.28.0.3.0 on Solaris 11.3 | Feb 6, 2018 | Dec 7, 2015 |
| Suse | — | Upgrade python-django | Dec 18, 2015 | Dec 7, 2015 |
| Ubuntu | — | Upgrade python-djangoUpgrade python3-django | Dec 7, 2015 | Nov 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub