Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

5.26.06.120252026202720282029

Недавние уязвимости Django

Количество 921

ubuntu логотип

CVE-2024-53908

почти 2 года назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-53907

почти 2 года назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-53907

почти 2 года назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-53908

почти 2 года назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2024-10874

почти 2 года назад

Уязвимость класса django.db.models.fields.json.HasKey программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный SQL-код

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2024-11394

почти 2 года назад

Уязвимость функции strip_tags() модуля django.utils.html программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rrqc-c2jx-6jgv

почти 2 года назад

Django allows enumeration of user e-mail addresses

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-5hgc-2vfp-mqvc

почти 2 года назад

Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2024-45231

почти 2 года назад

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The dja ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-45231

почти 2 года назад

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.8
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-53907

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-53907

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-53908

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.has_key lookup via __ are unaffected.)

CVSS3: 9.1
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-10874

Уязвимость класса django.db.models.fields.json.HasKey программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный SQL-код

CVSS3: 9.1
1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-11394

Уязвимость функции strip_tags() модуля django.utils.html программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-rrqc-c2jx-6jgv

Django allows enumeration of user e-mail addresses

CVSS3: 3.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-5hgc-2vfp-mqvc

Django vulnerable to denial-of-service attack via the urlize() and urlizetrunc() template filters

CVSS3: 5.3
26%
Средний
почти 2 года назад
debian логотип
CVE-2024-45231

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The dja ...

CVSS3: 5.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-45231

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).

CVSS3: 5.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться