Логотип exploitDog
product: "django"
Консоль
Логотип exploitDog

exploitDog

product: "django"
Django

Djangoсвободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC

Релизный цикл, информация об уязвимостях

Продукт: Django
Вендор: djangoproject

График релизов

4.25.05.15.26.02023202420252026202720282029

Недавние уязвимости Django

Количество 750

ubuntu логотип

CVE-2016-2513

почти 10 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2016-2512

почти 10 лет назад

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2016-2513

почти 10 лет назад

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2048

почти 10 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2016-2048

почти 10 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-2048

почти 10 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2016-00527

почти 10 лет назад

Уязвимость программной платформы для веб-приложений Django, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2016-2048

около 10 лет назад

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-8213

около 10 лет назад

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-8213

около 10 лет назад

The get_format function in utils/formats.py in Django before 1.7.x bef ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS3: 3.1
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-2512

The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

CVSS2: 5.8
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-2513

The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

CVSS2: 4.3
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, all ...

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
fstec логотип
BDU:2016-00527

Уязвимость программной платформы для веб-приложений Django, позволяющая нарушителю обойти существующие ограничения доступа

CVSS2: 6
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-2048

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote attackers to obtain sensitive application secrets via a settings key in place of a date/time format setting, as demonstrated by SECRET_KEY.

CVSS2: 5
3%
Низкий
около 10 лет назад
debian логотип
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x bef ...

CVSS2: 5
3%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться