Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9014

Опубликовано: 01 нояб. 2016
Источник: redhat
CVSS3: 7.4
CVSS2: 4
EPSS Низкий

Описание

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3calamari-serverWill not fix
Red Hat Ceph Storage 2python-djangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-djangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-djangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-djangoWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Toolspython-djangoWill not fix
Red Hat OpenStack Platform 10 (Newton)python-djangoWill not fix
Red Hat OpenStack Platform 10 (Newton) Operational Toolspython-djangoWill not fix
Red Hat OpenStack Platform 8 (Liberty)python-djangoWill not fix
Red Hat OpenStack Platform 8 (Liberty) Operational Toolspython-djangoWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1389417python-django: DNS rebinding vulnerability when 'DEBUG=True'

EPSS

Процентиль: 88%
0.04296
Низкий

7.4 High

CVSS3

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
nvd
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

CVSS3: 8.1
debian
больше 8 лет назад

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x bef ...

CVSS3: 8.1
github
около 3 лет назад

Django DNS Rebinding Vulnerability

suse-cvrf
около 7 лет назад

Security update for python-Django

EPSS

Процентиль: 88%
0.04296
Низкий

7.4 High

CVSS3

4 Medium

CVSS2