Количество 9
Количество 9

BDU:2024-06269
Уязвимость методов QuerySet.values() и values_list() моделей JSONField программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный код

CVE-2024-42005
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.

CVE-2024-42005
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.

CVE-2024-42005
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.
CVE-2024-42005
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2. ...
GHSA-pv4p-cwwg-4rph
Django SQL injection vulnerability
ELSA-2024-12803
ELSA-2024-12803: Oracle Linux Automation Manager 2.2 (MODERATE)

SUSE-SU-2024:2816-1
Security update for python-Django

SUSE-SU-2024:2817-1
Security update for python-Django
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | BDU:2024-06269 Уязвимость методов QuerySet.values() и values_list() моделей JSONField программной платформы для веб-приложений Django, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 0% Низкий | 11 месяцев назад |
![]() | CVE-2024-42005 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад |
![]() | CVE-2024-42005 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад |
![]() | CVE-2024-42005 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg. | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад |
CVE-2024-42005 An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2. ... | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад | |
GHSA-pv4p-cwwg-4rph Django SQL injection vulnerability | CVSS3: 9.1 | 0% Низкий | 11 месяцев назад | |
ELSA-2024-12803 ELSA-2024-12803: Oracle Linux Automation Manager 2.2 (MODERATE) | 8 месяцев назад | |||
![]() | SUSE-SU-2024:2816-1 Security update for python-Django | 11 месяцев назад | ||
![]() | SUSE-SU-2024:2817-1 Security update for python-Django | 11 месяцев назад |
Уязвимостей на страницу