python-django-registration: CVE-2021-21416

Related Vulnerabilities: CVE-2021-21416  

Debian Bug report logs - #987366
python-django-registration: CVE-2021-21416

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Thu, 22 Apr 2021 14:51:01 UTC

Severity: important

Tags: security, upstream

Found in versions python-django-registration/2.2-5, python-django-registration/2.2-2

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Python Team <team+python@tracker.debian.org>:
Bug#987366; Package src:python-django-registration. (Thu, 22 Apr 2021 14:51:02 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Python Team <team+python@tracker.debian.org>. (Thu, 22 Apr 2021 14:51:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: python-django-registration: CVE-2021-21416
Date: Thu, 22 Apr 2021 16:49:51 +0200
Source: python-django-registration
Version: 2.2-5
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Control: found -1 2.2-2

Hi,

The following vulnerability was published for python-django-registration.

CVE-2021-21416[0]:
| django-registration is a user registration package for Django. The
| django-registration package provides tools for implementing user-
| account registration flows in the Django web framework. In django-
| registration prior to 3.1.2, the base user-account registration view
| did not properly apply filters to sensitive data, with the result that
| sensitive data could be included in error reports rather than removed
| automatically by Django. Triggering this requires: A site is using
| django-registration &lt; 3.1.2, The site has detailed error reports
| (such as Django's emailed error reports to site staff/developers)
| enabled and a server-side error (HTTP 5xx) occurs during an attempt by
| a user to register an account. Under these conditions, recipients of
| the detailed error report will see all submitted data from the
| account-registration attempt, which may include the user's proposed
| credentials (such as a password).

The code has moved around a bit between the version we have and newest
upstream version, but the issue unless mistaken is present as well in
2.2. It is claimed indeed that it is before 3.1.2 upstream.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-21416
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21416
[1] https://github.com/ubernostrum/django-registration/security/advisories/GHSA-58c7-px5v-82hh
[2] https://github.com/ubernostrum/django-registration/commit/8206af081e239598cfd15d165d4d8ab9849ee23c

Regards,
Salvatore



Marked as found in versions python-django-registration/2.2-2. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Thu, 22 Apr 2021 14:51:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Apr 23 08:07:36 2021; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.