Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

5.26.020252026202720282029

Недавние уязвимости Django

Количество 900

debian логотип

CVE-2025-48432

около 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2025-48432

около 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2025-48432

около 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2025-06450

около 1 года назад

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01523-1

около 1 года назад

Security update for python-Django

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:1523-1

около 1 года назад

Security update for python-Django

EPSS: Средний
github логотип

GHSA-8j24-cjrq-gr2m

около 1 года назад

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2025-32873

около 1 года назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2025-32873

около 1 года назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
EPSS: Средний
ubuntu логотип

CVE-2025-32873

около 1 года назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
1%
Низкий
около 1 года назад
fstec логотип
BDU:2025-06450

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01523-1

Security update for python-Django

15%
Средний
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1523-1

Security update for python-Django

15%
Средний
около 1 года назад
github логотип
GHSA-8j24-cjrq-gr2m

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
15%
Средний
около 1 года назад
nvd логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
15%
Средний
около 1 года назад
debian логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
15%
Средний
около 1 года назад
ubuntu логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
15%
Средний
около 1 года назад

Уязвимостей на страницу


Поделиться