Описание
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 1:1.11.11-1ubuntu1.9 |
devel | released | 2:2.2.12-1ubuntu1 |
eoan | released | 1:1.11.22-1ubuntu1.4 |
esm-infra-legacy/trusty | not-affected | 1.6.11-0ubuntu1.3+esm1 |
esm-infra/bionic | not-affected | 1:1.11.11-1ubuntu1.9 |
esm-infra/focal | not-affected | 2:2.2.12-1ubuntu0.1 |
esm-infra/xenial | not-affected | 1.8.7-1ubuntu5.13 |
focal | released | 2:2.2.12-1ubuntu0.1 |
precise/esm | DNE | |
trusty | ignored | end of standard support |
Показывать по
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0 ...
Уязвимость библиотеки Django, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3