Bug 1157705 (CVE-2019-19118)

Summary: VUL-0: CVE-2019-19118: python-Django: Privilege escalation in the Django admin
Product: [Novell Products] SUSE Security Incidents Reporter: Wolfgang Frisch <wolfgang.frisch>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: atoptsoglou
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/247886/
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Comment 4 Wolfgang Frisch 2019-12-02 10:54:26 UTC
CVE-2019-19118

Privilege escalation in the Django admin.
=========================================================

Since Django 2.1, a Django model admin displaying a parent model with related
model inlines, where the user has view-only permissions to a parent model but
edit permissions to the inline model, would display a read-only view of the
parent model but editable forms for the inline.

Submitting these forms would not allow direct edits to the parent model, but
would trigger the parent model's ``save()`` method, and cause pre and post-save
signal handlers to be invoked. This is a privilege escalation as a user who
lacks permission to edit a model should not be able to trigger its save-related
signals.

To resolve this issue, the permission handling code of the Django admin
interface has been changed. Now, if a user has only the "view" permission for a
parent model, the entire displayed form will not be editable, even if the user
has permission to edit models included in inlines.

This is a backwards-incompatible change, and the Django security team is aware
that some users of Django were depending on the ability to allow editing of
inlines in the admin form of an otherwise view-only parent model.

Given the complexity of the Django admin, and in-particular the permissions
related checks, it is the view of the Django security team that this change was
necessary: that it is not currently feasible to maintain the existing behavior
whilst escaping the potential privilege escalation in a way that would avoid a
recurrence of similar issues in the future, and that would be compatible with
Django's *safe by default* philosophy.

For the time being, developers whose applications are affected by this change
should replace the use of inlines in read-only parents with custom forms and
views that explicitly implement the desired functionality. In the longer term,
adding a documented, supported, and properly-tested mechanism for
partially-editable multi-model forms to the admin interface may occur in Django
itself.

Thank you to Shen Ying for reporting this issue.

Affected supported versions
===========================

* Django master branch
* Django 3.0 (which will be released in a separate blog post later today)
* Django 2.2
* Django 2.1

Resolution
==========

Patches to resolve the issue have been applied to Django's master branch and
the 3.0, 2.2, and 2.1 release branches. The patches may be obtained from the following changesets:

* On the `master branch <https://github.com/django/django/commit/11c5e0609bcc0db93809de2a08e0dc3d70b393e4>`__
* On the `3.0 release branch <https://github.com/django/django/commit/092cd66cf3c3e175acce698d6ca2012068d878fa>`__
* On the `2.2 release branch <https://github.com/django/django/commit/36f580a17f0b3cb087deadf3b65eea024f479c21>`__
* On the `2.1 release branch <https://github.com/django/django/commit/103ebe2b5ff1b2614b85a52c239f471904d26244>`__

The following releases have been issued:

* Django 2.2.8 (`download Django 2.2.8 <https://www.djangoproject.com/m/releases/2.2/Django-2.2.8.tar.gz>`_ | `2.2.8 checksums <https://www.djangoproject.com/m/pgp/Django-2.2.8.checksum.txt>`_)
* Django 2.1.15 (`download Django 2.1.15 <https://www.djangoproject.com/m/releases/2.1/Django-2.1.15.tar.gz>`_ | `2.1.15 checksums <https://www.djangoproject.com/m/pgp/Django-2.1.15.checksum.txt>`_)

The PGP key ID used for these releases is Carlton Gibson: E17DF5C82B4F9D00.
Comment 5 Alberto Planas Dominguez 2019-12-02 12:38:00 UTC
Updated in Factory, and in Leap 15.1 (https://build.opensuse.org/request/show/752926)
Comment 6 Swamp Workflow Management 2019-12-03 14:00:21 UTC
This is an autogenerated message for OBS integration:
This bug (1157705) was mentioned in
https://build.opensuse.org/request/show/753252 15.1 / python-Django
Comment 7 Alberto Planas Dominguez 2019-12-04 09:57:56 UTC
TW and leap 15.1 merged the new code. I move back to sec-team, so you can validate it.
Comment 8 Alexandros Toptsoglou 2020-07-23 09:31:40 UTC
Done