Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f2c-jm6v-cr35

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Django DNS Rebinding Vulnerability

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.8a1, < 1.8.16

1.8.16

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.9a1, < 1.9.11

1.9.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.10a1, < 1.10.3

1.10.3

EPSS

Процентиль: 88%
0.04312
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 9 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 7.4
redhat
около 9 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
nvd
около 9 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
debian
около 9 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x bef ...

suse-cvrf
больше 7 лет назад

Security update for python-Django

EPSS

Процентиль: 88%
0.04312
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3