CVE-2019-13177
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.
El archivo verification.py en django-rest-registration (también conocida como biblioteca de registro REST de Django) anterior a la versión 0.5.0 consiste en una cadena estática para firmas (es decir, la API de firma de Django es usada inapropiadamente), lo que permite a los atacantes remotos suplantar el proceso de comprobación. Esto ocurre porque la refactorización del código incorrecta conllevó a llamar a una función crítica de seguridad con un argumento incorrecto.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-02 CVE Reserved
- 2019-07-02 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-11-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/apragacz/django-rest-registration/releases/tag/0.5.0 | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/apragacz/django-rest-registration/security/advisories/GHSA-p3w6-jcg4-52xh | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Django-rest-registration Project Search vendor "Django-rest-registration Project" | Django-rest-registration Search vendor "Django-rest-registration Project" for product "Django-rest-registration" | > 0.1.0 < 0.5.0 Search vendor "Django-rest-registration Project" for product "Django-rest-registration" and version " > 0.1.0 < 0.5.0" | django |
Affected
|