Django — свободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC
Релизный цикл, информация об уязвимостях
График релизов
Количество 679

CVE-2018-16984
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
CVE-2018-16984
An issue was discovered in Django 2.1 before 2.1.2, in which unprivile ...

CVE-2018-16984
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVE-2018-16984
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

openSUSE-SU-2018:2488-2
Security update for python-Django

openSUSE-SU-2018:2488-1
Security update for python-Django

openSUSE-SU-2018:2375-1
Security update for python-Django1

CVE-2018-14574
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CVE-2018-14574
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11 ...

CVE-2018-14574
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2018-16984 An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes. | CVSS3: 4.9 | 1% Низкий | почти 7 лет назад |
CVE-2018-16984 An issue was discovered in Django 2.1 before 2.1.2, in which unprivile ... | CVSS3: 4.9 | 1% Низкий | почти 7 лет назад | |
![]() | CVE-2018-16984 An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes. | CVSS3: 4.9 | 1% Низкий | почти 7 лет назад |
![]() | CVE-2018-16984 An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes. | CVSS3: 2.7 | 1% Низкий | почти 7 лет назад |
![]() | openSUSE-SU-2018:2488-2 Security update for python-Django | 12% Средний | около 7 лет назад | |
![]() | openSUSE-SU-2018:2488-1 Security update for python-Django | 12% Средний | около 7 лет назад | |
![]() | openSUSE-SU-2018:2375-1 Security update for python-Django1 | 12% Средний | около 7 лет назад | |
![]() | CVE-2018-14574 django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. | CVSS3: 6.1 | 12% Средний | около 7 лет назад |
CVE-2018-14574 django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11 ... | CVSS3: 6.1 | 12% Средний | около 7 лет назад | |
![]() | CVE-2018-14574 django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect. | CVSS3: 6.1 | 12% Средний | около 7 лет назад |
Уязвимостей на страницу