Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.26.02023202420252026202720282029

Недавние уязвимости Django

Количество 775

github логотип

GHSA-xxj9-f6rv-m3x4

около 2 лет назад

Django denial-of-service attack in the intcomma template filter

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-24680

около 2 лет назад

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-24680

около 2 лет назад

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-24680

около 2 лет назад

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-24680

около 2 лет назад

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-01517

около 2 лет назад

Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-22199

около 2 лет назад

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users' browsers when visiting affected web pages. The vulnerability has been addressed, the template engine now defaults to having autoescape set to `true`, effectively mitigating the risk of XSS attacks.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-4mq2-gc4j-cmw6

около 2 лет назад

Django Template Engine Vulnerable to XSS

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0390-1

около 2 лет назад

Security update for python-Django1

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0389-1

около 2 лет назад

Security update for python-Django1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-xxj9-f6rv-m3x4

Django denial-of-service attack in the intcomma template filter

CVSS3: 5.9
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-24680

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-24680

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10 ...

CVSS3: 7.5
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-24680

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-24680

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-01517

Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-22199

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users' browsers when visiting affected web pages. The vulnerability has been addressed, the template engine now defaults to having autoescape set to `true`, effectively mitigating the risk of XSS attacks.

CVSS3: 9.3
2%
Низкий
около 2 лет назад
github логотип
GHSA-4mq2-gc4j-cmw6

Django Template Engine Vulnerable to XSS

CVSS3: 9.3
2%
Низкий
около 2 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0390-1

Security update for python-Django1

3%
Низкий
около 2 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0389-1

Security update for python-Django1

3%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться