Django — свободный фреймворк для веб-приложений на языке Python, использующий шаблон проектирования MVC
Релизный цикл, информация об уязвимостях
График релизов
Количество 673
GHSA-xxj9-f6rv-m3x4
Django denial-of-service attack in the intcomma template filter
CVE-2024-24680
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10 ...

CVE-2024-24680
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVE-2024-24680
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

CVE-2024-24680
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

BDU:2024-01517
Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVE-2024-22199
This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users' browsers when visiting affected web pages. The vulnerability has been addressed, the template engine now defaults to having autoescape set to `true`, effectively mitigating the risk of XSS attacks.
GHSA-4mq2-gc4j-cmw6
Django Template Engine Vulnerable to XSS

openSUSE-SU-2023:0390-1
Security update for python-Django1

openSUSE-SU-2023:0389-1
Security update for python-Django1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-xxj9-f6rv-m3x4 Django denial-of-service attack in the intcomma template filter | CVSS3: 5.9 | 1% Низкий | больше 1 года назад | |
CVE-2024-24680 An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10 ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
![]() | CVE-2024-24680 An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-24680 An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-24680 An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
![]() | BDU:2024-01517 Уязвимость программной платформы для веб-приложений Django, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
![]() | CVE-2024-22199 This package provides universal methods to use multiple template engines with the Fiber web framework using the Views interface. This vulnerability specifically impacts web applications that render user-supplied data through this template engine, potentially leading to the execution of malicious scripts in users' browsers when visiting affected web pages. The vulnerability has been addressed, the template engine now defaults to having autoescape set to `true`, effectively mitigating the risk of XSS attacks. | CVSS3: 9.3 | 1% Низкий | больше 1 года назад |
GHSA-4mq2-gc4j-cmw6 Django Template Engine Vulnerable to XSS | CVSS3: 9.3 | 1% Низкий | больше 1 года назад | |
![]() | openSUSE-SU-2023:0390-1 Security update for python-Django1 | 2% Низкий | больше 1 года назад | |
![]() | openSUSE-SU-2023:0389-1 Security update for python-Django1 | 2% Низкий | больше 1 года назад |
Уязвимостей на страницу