CVE-2020-13254
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
- Djangoproject Django
- < 2.2.13, 3.0.7
- Fix
- Available
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 6.1% (93th percentile)
- Weakness
- CWE-295
- NVD status
- Modified
- Published
- 2020-06-03
CVE-2020-13254 at NVD
1 known exploit for CVE-2020-13254
Proof-of-concept code and exploit modules indexed by Sploitus