Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.26.02023202420252026202720282029

Недавние уязвимости Django

Количество 751

suse-cvrf логотип

openSUSE-SU-2023:0062-1

почти 3 года назад

Security update for python-Django

EPSS: Средний
github логотип

GHSA-2hrw-hx67-34x6

почти 3 года назад

Resource exhaustion in Django

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2023-24580

почти 3 года назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2023-24580

почти 3 года назад

An issue was discovered in the Multipart Request Parser in Django 3.2 ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2023-24580

почти 3 года назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2023-09100

почти 3 года назад

Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2023-24580

почти 3 года назад

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-q2jf-h9jm-m7p4

около 3 лет назад

Django contains Uncontrolled Resource Consumption via cached header

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-23969

около 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-23969

около 3 лет назад

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, t ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
openSUSE-SU-2023:0062-1

Security update for python-Django

25%
Средний
почти 3 года назад
github логотип
GHSA-2hrw-hx67-34x6

Resource exhaustion in Django

CVSS3: 7.5
25%
Средний
почти 3 года назад
nvd логотип
CVE-2023-24580

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
25%
Средний
почти 3 года назад
debian логотип
CVE-2023-24580

An issue was discovered in the Multipart Request Parser in Django 3.2 ...

CVSS3: 7.5
25%
Средний
почти 3 года назад
ubuntu логотип
CVE-2023-24580

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
25%
Средний
почти 3 года назад
fstec логотип
BDU:2023-09100

Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
25%
Средний
почти 3 года назад
redhat логотип
CVE-2023-24580

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs (e.g., an excessive number of parts) to multipart forms could result in too many open files or memory exhaustion, and provided a potential vector for a denial-of-service attack.

CVSS3: 7.5
25%
Средний
почти 3 года назад
github логотип
GHSA-q2jf-h9jm-m7p4

Django contains Uncontrolled Resource Consumption via cached header

CVSS3: 7.5
6%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repetitive parsing. This leads to a potential denial-of-service vector via excessive memory usage if the raw value of Accept-Language headers is very large.

CVSS3: 7.5
6%
Низкий
около 3 лет назад
debian логотип
CVE-2023-23969

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, t ...

CVSS3: 7.5
6%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться