DjangoÃÜÂë³ÁÖô¦µÄÕË»§½Ù³Ö·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-19

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19844£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Django < 1.11.27

Django 2.x < 2.2.9

Django 3.x < 3.0.1


·ì϶¸ÅÊö


DjangoÊÇDjango»ù½ð»áµÄÒ»Ì×»ùÓÚPython˵»°µÄ¿ªÔ´WebÀûÓÿò¼Ü¡£¸Ã¿ò¼ÜÔ̺¬ÃæÏò¶ÔÏóµÄÓ³ÉäÆ÷¡¢ÊÓͼϵͳ¡¢Ä£°åϵͳµÈ¡£


Django ÔÚ2019Äê12ÔÂ18ÈÕ½øÐÐÁ˰²È«²¹¶¡¸üÐÂ, ½¨¸´ÁËÒ»¸öÃÜÂë³ÁÖô¦µÄÕË»§½Ù³Ö·ì϶¡£¸Ã·ì϶ÓÉÓÚDjangoµÄÃÜÂë³ÁÖÃÖ°Äܲ»·Ö±æ´óÓ×дµÄÀ´¶ÔÊý¾Ý¿â½øÐÐÓÊÏ䵨ַ²éÎÊ£¬ÔÚ´¦ÖÃUnicodeµÄ´óÓ×дת»»Ê±´æÔÚ½âÎöÎÊÌ⣬¿ÉÄܻᵼÖÂÕË»§½Ù³ÖÎÊÌâ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬Çë¸üÐÂDjango°æ±¾µ½3.0.1¡¢2.2.9¡¢1.11.27£ºhttps://www.djangoproject.com/weblog/2019/dec/18/security-releases/¡£


²Î¿¼Á´½Ó


https://www.djangoproject.com/weblog/2019/dec/18/security-releases/