4.3

CVE-2015-5144

Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.

Data is provided by the National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version15.04
CanonicalUbuntu Linux Version15.10
DjangoprojectDjango Version <= 1.4.20
DjangoprojectDjango Version1.5
DjangoprojectDjango Version1.5 Updatealpha
DjangoprojectDjango Version1.5 Updatebeta
DjangoprojectDjango Version1.5.1
DjangoprojectDjango Version1.5.2
DjangoprojectDjango Version1.5.3
DjangoprojectDjango Version1.5.4
DjangoprojectDjango Version1.5.5
DjangoprojectDjango Version1.5.6
DjangoprojectDjango Version1.5.7
DjangoprojectDjango Version1.5.8
DjangoprojectDjango Version1.5.9
DjangoprojectDjango Version1.5.10
DjangoprojectDjango Version1.5.11
DjangoprojectDjango Version1.5.12
DjangoprojectDjango Version1.6 Update-
DjangoprojectDjango Version1.6 Updatebeta1
DjangoprojectDjango Version1.6 Updatebeta2
DjangoprojectDjango Version1.6 Updatebeta3
DjangoprojectDjango Version1.6 Updatebeta4
DjangoprojectDjango Version1.6.1
DjangoprojectDjango Version1.6.2
DjangoprojectDjango Version1.6.3
DjangoprojectDjango Version1.6.4
DjangoprojectDjango Version1.6.5
DjangoprojectDjango Version1.6.6
DjangoprojectDjango Version1.6.7
DjangoprojectDjango Version1.6.8
DjangoprojectDjango Version1.6.9
DjangoprojectDjango Version1.6.10
DjangoprojectDjango Version1.7 Updatebeta1
DjangoprojectDjango Version1.7 Updatebeta2
DjangoprojectDjango Version1.7 Updatebeta3
DjangoprojectDjango Version1.7 Updatebeta4
DjangoprojectDjango Version1.7 Updaterc1
DjangoprojectDjango Version1.7 Updaterc2
DjangoprojectDjango Version1.7 Updaterc3
DjangoprojectDjango Version1.7.1
DjangoprojectDjango Version1.7.2
DjangoprojectDjango Version1.7.3
DjangoprojectDjango Version1.7.4
DjangoprojectDjango Version1.7.5
DjangoprojectDjango Version1.7.6
DjangoprojectDjango Version1.7.7
DjangoprojectDjango Version1.7.8
DjangoprojectDjango Version1.7.9
DjangoprojectDjango Version1.8 Updatebeta1
DjangoprojectDjango Version1.8.0
DjangoprojectDjango Version1.8.1
DjangoprojectDjango Version1.8.2
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
OracleSolaris Version11.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.24% 0.84
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.