Логотип exploitDog
bind:CVE-2025-48432
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48432

Количество 9

Количество 9

ubuntu логотип

CVE-2025-48432

6 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2025-48432

6 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-48432

6 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-48432

6 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02248-1

5 месяцев назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01952-1

6 месяцев назад

Security update for python-Django

EPSS: Низкий
github логотип

GHSA-7xr5-9hcq-chf9

6 месяцев назад

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
EPSS: Низкий
fstec логотип

BDU:2025-06450

6 месяцев назад

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
EPSS: Низкий
redos логотип

ROS-20250924-06

2 месяца назад

Множественные уязвимости python3-django

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02248-1

Security update for python-Django

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:01952-1

Security update for python-Django

0%
Низкий
6 месяцев назад
github логотип
GHSA-7xr5-9hcq-chf9

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2025-06450

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
0%
Низкий
6 месяцев назад
redos логотип
ROS-20250924-06

Множественные уязвимости python3-django

CVSS3: 7.1
2 месяца назад

Уязвимостей на страницу