DjangoÃÜÂë³ÁÖô¦µÄÕË»§½Ù³Ö·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2019-12-19·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19844£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Django < 1.11.27
Django 2.x < 2.2.9
Django 3.x < 3.0.1
·ì϶¸ÅÊö
DjangoÊÇDjango»ù½ð»áµÄÒ»Ì×»ùÓÚPython˵»°µÄ¿ªÔ´WebÀûÓÿò¼Ü¡£¸Ã¿ò¼ÜÔ̺¬ÃæÏò¶ÔÏóµÄÓ³ÉäÆ÷¡¢ÊÓͼϵͳ¡¢Ä£°åϵͳµÈ¡£
Django ÔÚ2019Äê12ÔÂ18ÈÕ½øÐÐÁ˰²È«²¹¶¡¸üÐÂ, ½¨¸´ÁËÒ»¸öÃÜÂë³ÁÖô¦µÄÕË»§½Ù³Ö·ì϶¡£¸Ã·ì϶ÓÉÓÚDjangoµÄÃÜÂë³ÁÖÃÖ°Äܲ»·Ö±æ´óÓ×дµÄÀ´¶ÔÊý¾Ý¿â½øÐÐÓÊÏ䵨ַ²éÎÊ£¬ÔÚ´¦ÖÃUnicodeµÄ´óÓ×дת»»Ê±´æÔÚ½âÎöÎÊÌ⣬¿ÉÄܻᵼÖÂÕË»§½Ù³ÖÎÊÌâ¡£
·ì϶ÑéÖ¤
ÔÝÎÞPOC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡£¬Çë¸üÐÂDjango°æ±¾µ½3.0.1¡¢2.2.9¡¢1.11.27£ºhttps://www.djangoproject.com/weblog/2019/dec/18/security-releases/¡£
²Î¿¼Á´½Ó
https://www.djangoproject.com/weblog/2019/dec/18/security-releases/


¾©¹«Íø°²±¸11010802024551ºÅ