DjangoÃÜÂëÖØÖô¦µÄÕË»§Ð®ÖÆÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-19Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19844£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Django < 1.11.27
Django 2.x < 2.2.9
Django 3.x < 3.0.1
Îó²î¸ÅÊö
DjangoÊÇDjango»ù½ð»áµÄÒ»Ì×»ùÓÚPythonÓïÑԵĿªÔ´WebÓ¦Óÿò¼Ü¡£¡£¡£¡£¸Ã¿ò¼Ü°üÀ¨ÃæÏò¹¤¾ßµÄÓ³ÉäÆ÷¡¢ÊÓͼϵͳ¡¢Ä£°åϵͳµÈ¡£¡£¡£¡£
Django ÔÚ2019Äê12ÔÂ18ÈÕ¾ÙÐÐÁËÇå¾²²¹¶¡¸üÐÂ, ÐÞ¸´ÁËÒ»¸öÃÜÂëÖØÖô¦µÄÕË»§Ð®ÖÆÎó²î¡£¡£¡£¡£¸ÃÎó²îÓÉÓÚDjangoµÄÃÜÂëÖØÖù¦Ð§²»Çø·Ö¾ÞϸдµÄÀ´¶ÔÊý¾Ý¿â¾ÙÐÐÓÊÏ䵨µãÅÌÎÊ£¬£¬£¬ÔÚ´¦Öóͷ£UnicodeµÄ¾Þϸдת»»Ê±±£´æÆÊÎöÎÊÌ⣬£¬£¬¿ÉÄܻᵼÖÂÕË»§Ð®ÖÆÎÊÌâ¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡£¬£¬£¬Çë¸üÐÂDjango°æ±¾µ½3.0.1¡¢2.2.9¡¢1.11.27£ºhttps://www.djangoproject.com/weblog/2019/dec/18/security-releases/¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.djangoproject.com/weblog/2019/dec/18/security-releases/