Количество 900
Количество 900
GHSA-8qcx-xf44-272x
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.
GHSA-8p8v-wh79-9r56
Django vulnerable to Uncontrolled Resource Consumption
GHSA-8m3r-rv5g-fcpq
Cross-site scripting in django
GHSA-8j24-cjrq-gr2m
Django has a denial-of-service possibility in strip_tags()
GHSA-8cjm-8mp7-r2xf
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue.
GHSA-8c5j-9r9f-c6w8
Information disclosure in Django
GHSA-89hj-xfx5-7q66
Django Reuses Cached CSRF Token
GHSA-8498-2h75-472j
Django denial-of-service in django.utils.html.strip_tags()
GHSA-7xr5-9hcq-chf9
Django Improper Output Neutralization for Logs vulnerability
GHSA-7wph-fc4w-wqp2
Improper date handling in Django
GHSA-7rp2-fm2h-wchj
Django Cross-site Scripting in AdminURLFieldWidget
GHSA-7qfw-j7hp-v45g
Django WSGI Header Spoofing Vulnerability
GHSA-7h4p-27mh-hmrw
Django Denial of service vulnerability in django.utils.encoding.uri_to_iri
GHSA-7h2m-m8vj-598h
Django Uses Persistent Cookies Containing Sensitive Information
GHSA-7g9h-c88w-r7h2
Directory traversal in Django
GHSA-7fq8-4pv5-5w5c
Django cross-site scripting (XSS) attack via user-supplied redirect URLs
GHSA-795c-9xpc-xw6g
Django vulnerable to a denial-of-service attack
GHSA-78vx-ggch-wghm
Django Allows Redirect via Data URL
GHSA-6wgp-fwfm-mxp3
Django allows user sessions hijacking via an empty string in the session key
GHSA-6wcr-wcqm-3mfh
Django settings leak in date template filter
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8qcx-xf44-272x An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue. | CVSS3: 6.1 | 0% Низкий | 24 дня назад | |
GHSA-8p8v-wh79-9r56 Django vulnerable to Uncontrolled Resource Consumption | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
GHSA-8m3r-rv5g-fcpq Cross-site scripting in django | CVSS3: 6.1 | 3% Низкий | около 8 лет назад | |
GHSA-8j24-cjrq-gr2m Django has a denial-of-service possibility in strip_tags() | CVSS3: 5.3 | 14% Средний | около 1 года назад | |
GHSA-8cjm-8mp7-r2xf An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitively, which allows remote attackers to read responses that were incorrectly cached because their `Cache-Control` directives used uppercase or mixed-case values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Ahmed Badawe for reporting this issue. | CVSS3: 3.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-8c5j-9r9f-c6w8 Information disclosure in Django | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-89hj-xfx5-7q66 Django Reuses Cached CSRF Token | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-8498-2h75-472j Django denial-of-service in django.utils.html.strip_tags() | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-7xr5-9hcq-chf9 Django Improper Output Neutralization for Logs vulnerability | CVSS3: 4 | 1% Низкий | около 1 года назад | |
GHSA-7wph-fc4w-wqp2 Improper date handling in Django | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
GHSA-7rp2-fm2h-wchj Django Cross-site Scripting in AdminURLFieldWidget | CVSS3: 6.1 | 2% Низкий | около 7 лет назад | |
GHSA-7qfw-j7hp-v45g Django WSGI Header Spoofing Vulnerability | CVSS3: 5.3 | 7% Низкий | около 4 лет назад | |
GHSA-7h4p-27mh-hmrw Django Denial of service vulnerability in django.utils.encoding.uri_to_iri | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-7h2m-m8vj-598h Django Uses Persistent Cookies Containing Sensitive Information | 1% Низкий | 3 месяца назад | ||
GHSA-7g9h-c88w-r7h2 Directory traversal in Django | CVSS3: 9.1 | 3% Низкий | около 8 лет назад | |
GHSA-7fq8-4pv5-5w5c Django cross-site scripting (XSS) attack via user-supplied redirect URLs | CVSS3: 6.1 | 5% Низкий | около 4 лет назад | |
GHSA-795c-9xpc-xw6g Django vulnerable to a denial-of-service attack | CVSS3: 5.3 | 1% Низкий | почти 2 года назад | |
GHSA-78vx-ggch-wghm Django Allows Redirect via Data URL | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-6wgp-fwfm-mxp3 Django allows user sessions hijacking via an empty string in the session key | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-6wcr-wcqm-3mfh Django settings leak in date template filter | CVSS3: 2.8 | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу