CVE-2023-5457CWE-1269

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug”…

High · published March 5, 2024

CVSS v3.1
7.5
EPSS
1%
Percentile
48.6
In the wild
Unconfirmed
What it is

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00644 · 48.6th percentile
Weakness
CWE-1269 · Product Released in Non-Release Configuration
Published
2024-03-05T11:15Z
EPSS history
Timeline
  • 05 MAR 11:15Z
    A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug”…
    cvelistv5