Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f2c-jm6v-cr35

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Django DNS Rebinding Vulnerability

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.8a1, < 1.8.16

1.8.16

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.9a1, < 1.9.11

1.9.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.10a1, < 1.10.3

1.10.3

EPSS

Процентиль: 88%
0.04296
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 7.4
redhat
почти 9 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
nvd
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
debian
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x bef ...

suse-cvrf
больше 7 лет назад

Security update for python-Django

EPSS

Процентиль: 88%
0.04296
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3