| | 282 | === Unhandled exception === |
| | 283 | |
| | 284 | Hello, |
| | 285 | |
| | 286 | Thank you for your report. |
| | 287 | |
| | 288 | An unhandled exception on its own isn't a security vulnerability. A stack trace or 500 error just means something crashed, not that there's a security impact. For us to treat this as a vulnerability, we'd need to see something beyond the crash: an unauthenticated attacker can trigger it cheaply and repeatedly with real effect on the service, or it exposes data that shouldn't be exposed, or it bypasses a security control. |
| | 289 | |
| | 290 | If you can demonstrate that, please resubmit and we'll take another look. |
| | 291 | |
| | 292 | Kind regards, the Django Security Team. |
| | 293 | |