PT-2026-97495 · Postgresql Global Development Group+1 · Postgresql+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The
HostList.list() function catches generic exceptions and returns the error string verbatim. An authenticated user can exploit this via the host filter parameter to trigger a Django FieldError, which leaks the complete Host model relation graph and internal reverse accessors, or a PostgreSQL DataError, which leaks raw database error strings. This can be achieved using primitives such as credential search=x to dump the ORM schema or name regex=[bad to reflect PostgreSQL errors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Django
Postgresql