@beyondmachines1@infosec.exchange
Post #4412584
2026-08-06 09:01 UTC
Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities
Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.
**If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L
Replies (0)
No replies.