Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Python

Pythonвысокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.

Релизный цикл, информация об уязвимостях

Продукт: Python
Вендор: python

График релизов

3.103.113.123.133.1420212022202320242025202620272028202920302031

Недавние уязвимости Python

Количество 1 104

github логотип

GHSA-9gg6-cm3f-wf38

около 5 лет назад

Incorrect Calculation and Use of Insufficiently Random Values in Python

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2021:1557-1

около 5 лет назад

Security update for python3

EPSS: Низкий
nvd логотип

CVE-2021-32052

около 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-32052

около 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 ( ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-32052

около 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-29921

около 5 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2021-29921

около 5 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2021-29921

около 5 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2021-32052

около 5 лет назад

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:1490-1

около 5 лет назад

Security update for python36

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9gg6-cm3f-wf38

Incorrect Calculation and Use of Insufficiently Random Values in Python

CVSS3: 5.9
13%
Средний
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1557-1

Security update for python3

2%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
3%
Низкий
около 5 лет назад
debian логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 ( ...

CVSS3: 6.1
3%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 6.1
3%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-29921

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
7%
Низкий
около 5 лет назад
debian логотип
CVE-2021-29921

In Python before 3,9,5, the ipaddress library mishandles leading zero ...

CVSS3: 9.8
7%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-29921

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
7%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-32052

In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP headers.

CVSS3: 7.4
3%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:1490-1

Security update for python36

2%
Низкий
около 5 лет назад

Уязвимостей на страницу


Поделиться