SCA: security update for django-registration (GHSA-58c7-px5v-82hh)

low Tenable Self-Hosted Container Security Plugin ID 410688

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- django-registration is a user registration package for Django. The django-registration package provides
tools for implementing user-account registration flows in the Django web framework. In django-registration
prior to 3.1.2, the base user-account registration view did not properly apply filters to sensitive data,
with the result that sensitive data could be included in error reports rather than removed automatically
by Django. Triggering this requires: A site is using django-registration < 3.1.2, The site has detailed
error reports (such as Django's emailed error reports to site staff/developers) enabled and a server-side
error (HTTP 5xx) occurs during an attempt by a user to register an account. Under these conditions,
recipients of the detailed error report will see all submitted data from the account-registration attempt,
which may include the user's proposed credentials (such as a password). (CVE-2021-21416)

See Also

https://github.com/advisories/GHSA-58c7-px5v-82hh

Plugin Details

Severity: Low

ID: 410688

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.6

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2021-21416

CVSS v3

Risk Factor: Low

Base Score: 2.6

Temporal Score: 2.3

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2

Threat Score: 0.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/6/2021

Vulnerability Publication Date: 4/1/2021

Reference Information

CVE: CVE-2021-21416