Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

5.26.020252026202720282029

Недавние уязвимости Django

Количество 900

ubuntu логотип

CVE-2023-36053

около 3 лет назад

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-36053

около 3 лет назад

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-04481

около 3 лет назад

Уязвимость компонентов EmailValidator и URLValidator программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r3xc-prgr-mg9p

около 3 лет назад

Django bypasses validation when using one form field to upload multiple files

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-31047

около 3 лет назад

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-31047

около 3 лет назад

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, i ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-31047

около 3 лет назад

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2023-31047

около 3 лет назад

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0075-1

больше 3 лет назад

Security update for python-Django

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2023:0062-1

больше 3 лет назад

Security update for python-Django

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2023-36053

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-36053

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
3%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-04481

Уязвимость компонентов EmailValidator и URLValidator программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
3%
Низкий
около 3 лет назад
github логотип
GHSA-r3xc-prgr-mg9p

Django bypasses validation when using one form field to upload multiple files

CVSS3: 9.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, i ...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-31047

In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0075-1

Security update for python-Django

63%
Средний
больше 3 лет назад
suse-cvrf логотип
openSUSE-SU-2023:0062-1

Security update for python-Django

63%
Средний
больше 3 лет назад

Уязвимостей на страницу


Поделиться