Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.22023202420252026202720282029

Недавние уязвимости Django

Количество 679

redhat логотип

CVE-2016-2513

больше 9 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-2512

больше 9 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2016-00527

больше 9 лет назад

Уязвимость программной платформы для веб-приложений Django, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2016-2048

больше 9 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-8213

больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-8213

больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x bef ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-8213

больше 9 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
fstec логотип
BDU:2016-00527

Уязвимость программной платформы для веб-приложений Django, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 6
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS2: 3.5
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
3%
Низкий
больше 9 лет назад
debian логотип
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x bef ...

CVSS2: 5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
3%
Низкий
больше 9 лет назад

Уязвимостей на страницу


Поделиться