Логотип exploitDog
bind:"CVE-2025-48432"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-48432"

Количество 8

Количество 8

ubuntu логотип

CVE-2025-48432

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2025-48432

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-48432

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-48432

около 2 месяцев назад

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02248-1

26 дней назад

Security update for python-Django

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:01952-1

около 2 месяцев назад

Security update for python-Django

EPSS: Низкий
github логотип

GHSA-7xr5-9hcq-chf9

около 2 месяцев назад

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
EPSS: Низкий
fstec логотип

BDU:2025-06450

2 месяца назад

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.

CVSS3: 4
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-48432

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, ...

CVSS3: 4
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02248-1

Security update for python-Django

0%
Низкий
26 дней назад
suse-cvrf логотип
SUSE-SU-2025:01952-1

Security update for python-Django

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7xr5-9hcq-chf9

Django Improper Output Neutralization for Logs vulnerability

CVSS3: 4
0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2025-06450

Уязвимость функции django.utils.log.log_response() программной платформы для веб-приложений Django, позволяющая нарушителю получить доступ на изменение данных в журнале

CVSS3: 4
0%
Низкий
2 месяца назад

Уязвимостей на страницу