DjangoÃÜÂëÖØÖô¦µÄÕË»§Ð®ÖÆÎó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2019-12-19

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19844£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Django < 1.11.27

Django 2.x < 2.2.9

Django 3.x < 3.0.1


Îó²î¸ÅÊö


DjangoÊÇDjango»ù½ð»áµÄÒ»Ì×»ùÓÚPythonÓïÑԵĿªÔ´WebÓ¦Óÿò¼Ü¡£¡£¡£¡£¸Ã¿ò¼Ü°üÀ¨ÃæÏò¹¤¾ßµÄÓ³ÉäÆ÷¡¢ÊÓͼϵͳ¡¢Ä£°åϵͳµÈ¡£¡£¡£¡£


Django ÔÚ2019Äê12ÔÂ18ÈÕ¾ÙÐÐÁËÇå¾²²¹¶¡¸üÐÂ, ÐÞ¸´ÁËÒ»¸öÃÜÂëÖØÖô¦µÄÕË»§Ð®ÖÆÎó²î¡£¡£¡£¡£¸ÃÎó²îÓÉÓÚDjangoµÄÃÜÂëÖØÖù¦Ð§²»Çø·Ö¾ÞϸдµÄÀ´¶ÔÊý¾Ý¿â¾ÙÐÐÓÊÏ䵨µãÅÌÎÊ£¬£¬£¬ÔÚ´¦Öóͷ£UnicodeµÄ¾Þϸдת»»Ê±±£´æÆÊÎöÎÊÌ⣬£¬£¬¿ÉÄܻᵼÖÂÕË»§Ð®ÖÆÎÊÌâ¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¬£¬£¬Çë¸üÐÂDjango°æ±¾µ½3.0.1¡¢2.2.9¡¢1.11.27£ºhttps://www.djangoproject.com/weblog/2019/dec/18/security-releases/¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.djangoproject.com/weblog/2019/dec/18/security-releases/