Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 727

github логотип

GHSA-7xr5-9hcq-chf9

5 месяцев назад

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-48432

5 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-48432

5 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2025-48432

5 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2025-48432

5 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2025-06450

5 месяцев назад

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01523-1

5 месяцев назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1523-1

6 месяцев назад

Security update for python-Django

EPSS: Низкий
github логотип

GHSA-8j24-cjrq-gr2m

6 месяцев назад

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-32873

6 месяцев назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-7xr5-9hcq-chf9

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-06450

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01523-1

Security update for python-Django

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1523-1

Security update for python-Django

0%
Низкий
6 месяцев назад
github логотип
GHSA-8j24-cjrq-gr2m

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться