Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 679

nvd логотип

CVE-2018-16984

почти 7 лет назад

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2018-16984

почти 7 лет назад

An issue was discovered in Django 2.1 before 2.1.2, in which unprivile ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2018-16984

почти 7 лет назад

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2018-16984

почти 7 лет назад

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 2.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:2488-2

около 7 лет назад

Security update for python-Django

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2018:2488-1

около 7 лет назад

Security update for python-Django

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2018:2375-1

около 7 лет назад

Security update for python-Django1

EPSS: Средний
nvd логотип

CVE-2018-14574

около 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2018-14574

около 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11 ...

CVSS3: 6.1
EPSS: Средний
ubuntu логотип

CVE-2018-14574

около 7 лет назад

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-16984

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 4.9
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-16984

An issue was discovered in Django 2.1 before 2.1.2, in which unprivile ...

CVSS3: 4.9
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2018-16984

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 4.9
1%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-16984

An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.

CVSS3: 2.7
1%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2488-2

Security update for python-Django

12%
Средний
около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2488-1

Security update for python-Django

12%
Средний
около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2375-1

Security update for python-Django1

12%
Средний
около 7 лет назад
nvd логотип
CVE-2018-14574

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
12%
Средний
около 7 лет назад
debian логотип
CVE-2018-14574

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11 ...

CVSS3: 6.1
12%
Средний
около 7 лет назад
ubuntu логотип
CVE-2018-14574

django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.

CVSS3: 6.1
12%
Средний
около 7 лет назад

Уязвимостей на страницу


Поделиться