Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

5.26.06.120252026202720282029

Недавние уязвимости Django

Количество 921

debian логотип

CVE-2025-48432

больше 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-48432

больше 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2025-48432

больше 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2025-48432

больше 1 года назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2025-06450

больше 1 года назад

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01523-1

больше 1 года назад

Security update for python-Django

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:1523-1

больше 1 года назад

Security update for python-Django

EPSS: Средний
github логотип

GHSA-8j24-cjrq-gr2m

больше 1 года назад

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2025-32873

больше 1 года назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2025-32873

больше 1 года назад

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-06450

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
1%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:01523-1

Security update for python-Django

14%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:1523-1

Security update for python-Django

14%
Средний
больше 1 года назад
github логотип
GHSA-8j24-cjrq-gr2m

Django has a denial-of-service possibility in strip_tags()

CVSS3: 5.3
14%
Средний
больше 1 года назад
debian логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, ...

CVSS3: 5.3
14%
Средний
больше 1 года назад
nvd логотип
CVE-2025-32873

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of incomplete HTML tags. The template filter striptags is also vulnerable, because it is built on top of strip_tags().

CVSS3: 5.3
14%
Средний
больше 1 года назад

Уязвимостей на страницу


Поделиться