Количество 921
Количество 921
GHSA-923m-gv2p-w5qp
Django: has_vary_header may expose cached responses when Vary values contain whitespace
GHSA-8x94-hmjh-97hq
Django vulnerable to Reflected File Download attack
GHSA-8rmj-xgq5-w9qm
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue.
GHSA-8qcx-xf44-272x
Django: DomainNameValidator permits newline characters that may enable HTTP header injection
GHSA-8p8v-wh79-9r56
Django vulnerable to Uncontrolled Resource Consumption
GHSA-8m3r-rv5g-fcpq
Cross-site scripting in django
GHSA-8j24-cjrq-gr2m
Django has a denial-of-service possibility in strip_tags()
GHSA-8cjm-8mp7-r2xf
Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling
GHSA-8c5j-9r9f-c6w8
Information disclosure in Django
GHSA-89hj-xfx5-7q66
Django Reuses Cached CSRF Token
GHSA-8498-2h75-472j
Django denial-of-service in django.utils.html.strip_tags()
GHSA-7xr5-9hcq-chf9
Django Improper Output Neutralization for Logs vulnerability
GHSA-7wph-fc4w-wqp2
Improper date handling in Django
GHSA-7rp2-fm2h-wchj
Django Cross-site Scripting in AdminURLFieldWidget
GHSA-7qfw-j7hp-v45g
Django WSGI Header Spoofing Vulnerability
GHSA-7h4p-27mh-hmrw
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
GHSA-7h2m-m8vj-598h
Django Uses Persistent Cookies Containing Sensitive Information
GHSA-7g9h-c88w-r7h2
Directory traversal in Django
GHSA-7fq8-4pv5-5w5c
Django cross-site scripting (XSS) attack via user-supplied redirect URLs
GHSA-795c-9xpc-xw6g
Django vulnerable to a denial-of-service attack
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-923m-gv2p-w5qp Django: has_vary_header may expose cached responses when Vary values contain whitespace | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
GHSA-8x94-hmjh-97hq Django vulnerable to Reflected File Download attack | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-8rmj-xgq5-w9qm An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue. | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
GHSA-8qcx-xf44-272x Django: DomainNameValidator permits newline characters that may enable HTTP header injection | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-8p8v-wh79-9r56 Django vulnerable to Uncontrolled Resource Consumption | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
GHSA-8m3r-rv5g-fcpq Cross-site scripting in django | CVSS3: 6.1 | 3% Низкий | около 8 лет назад | |
GHSA-8j24-cjrq-gr2m Django has a denial-of-service possibility in strip_tags() | CVSS3: 5.3 | 14% Средний | больше 1 года назад | |
GHSA-8cjm-8mp7-r2xf Django: UpdateCacheMiddleware may disclose cached responses due to case-sensitive Cache-Control handling | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
GHSA-8c5j-9r9f-c6w8 Information disclosure in Django | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-89hj-xfx5-7q66 Django Reuses Cached CSRF Token | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-8498-2h75-472j Django denial-of-service in django.utils.html.strip_tags() | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
GHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerability | CVSS3: 4 | 1% Низкий | больше 1 года назад | |
GHSA-7wph-fc4w-wqp2 Improper date handling in Django | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
GHSA-7rp2-fm2h-wchj Django Cross-site Scripting in AdminURLFieldWidget | CVSS3: 6.1 | 2% Низкий | больше 7 лет назад | |
GHSA-7qfw-j7hp-v45g Django WSGI Header Spoofing Vulnerability | CVSS3: 5.3 | 7% Низкий | больше 4 лет назад | |
GHSA-7h4p-27mh-hmrw Django Denial of service vulnerability in django.utils.encoding.uri_to_iri | CVSS3: 5.3 | 2% Низкий | почти 3 года назад | |
GHSA-7h2m-m8vj-598h Django Uses Persistent Cookies Containing Sensitive Information | 1% Низкий | 4 месяца назад | ||
GHSA-7g9h-c88w-r7h2 Directory traversal in Django | CVSS3: 9.1 | 3% Низкий | около 8 лет назад | |
GHSA-7fq8-4pv5-5w5c Django cross-site scripting (XSS) attack via user-supplied redirect URLs | CVSS3: 6.1 | 5% Низкий | больше 4 лет назад | |
GHSA-795c-9xpc-xw6g Django vulnerable to a denial-of-service attack | CVSS3: 5.3 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу