Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-35192

3 месяца назад

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Res ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7h2m-m8vj-598h

3 месяца назад

Django Uses Persistent Cookies Containing Sensitive Information

EPSS: Низкий
fstec логотип

BDU:2026-09702

3 месяца назад

Уязвимость программной платформы для веб-приложений Django, связанная с возможностью отправки файла cookie-сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260624-73-0012

около 1 месяца назад

Уязвимость python-django

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20704-1

3 месяца назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1740-1

3 месяца назад

Security update for python-Django

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker can steal a user's session after that user visits a cached public page. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Cantina for reporting this issue.

CVSS3: 6.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Res ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-7h2m-m8vj-598h

Django Uses Persistent Cookies Containing Sensitive Information

1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09702

Уязвимость программной платформы для веб-приложений Django, связанная с возможностью отправки файла cookie-сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260624-73-0012

Уязвимость python-django

CVSS3: 5.3
1%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20704-1

Security update for python-Django

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1740-1

Security update for python-Django

3 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.