4.3
CVE-2015-5144
- EPSS 2.24%
- Veröffentlicht 14.07.2015 17:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version12.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version15.04
Canonical ≫ Ubuntu Linux Version15.10
Djangoproject ≫ Django Version <= 1.4.20
Djangoproject ≫ Django Version1.5
Djangoproject ≫ Django Version1.5 Updatealpha
Djangoproject ≫ Django Version1.5 Updatebeta
Djangoproject ≫ Django Version1.5.1
Djangoproject ≫ Django Version1.5.2
Djangoproject ≫ Django Version1.5.3
Djangoproject ≫ Django Version1.5.4
Djangoproject ≫ Django Version1.5.5
Djangoproject ≫ Django Version1.5.6
Djangoproject ≫ Django Version1.5.7
Djangoproject ≫ Django Version1.5.8
Djangoproject ≫ Django Version1.5.9
Djangoproject ≫ Django Version1.5.10
Djangoproject ≫ Django Version1.5.11
Djangoproject ≫ Django Version1.5.12
Djangoproject ≫ Django Version1.6 Update-
Djangoproject ≫ Django Version1.6 Updatebeta1
Djangoproject ≫ Django Version1.6 Updatebeta2
Djangoproject ≫ Django Version1.6 Updatebeta3
Djangoproject ≫ Django Version1.6 Updatebeta4
Djangoproject ≫ Django Version1.6.1
Djangoproject ≫ Django Version1.6.2
Djangoproject ≫ Django Version1.6.3
Djangoproject ≫ Django Version1.6.4
Djangoproject ≫ Django Version1.6.5
Djangoproject ≫ Django Version1.6.6
Djangoproject ≫ Django Version1.6.7
Djangoproject ≫ Django Version1.6.8
Djangoproject ≫ Django Version1.6.9
Djangoproject ≫ Django Version1.6.10
Djangoproject ≫ Django Version1.7 Updatebeta1
Djangoproject ≫ Django Version1.7 Updatebeta2
Djangoproject ≫ Django Version1.7 Updatebeta3
Djangoproject ≫ Django Version1.7 Updatebeta4
Djangoproject ≫ Django Version1.7 Updaterc1
Djangoproject ≫ Django Version1.7 Updaterc2
Djangoproject ≫ Django Version1.7 Updaterc3
Djangoproject ≫ Django Version1.7.1
Djangoproject ≫ Django Version1.7.2
Djangoproject ≫ Django Version1.7.3
Djangoproject ≫ Django Version1.7.4
Djangoproject ≫ Django Version1.7.5
Djangoproject ≫ Django Version1.7.6
Djangoproject ≫ Django Version1.7.7
Djangoproject ≫ Django Version1.7.8
Djangoproject ≫ Django Version1.7.9
Djangoproject ≫ Django Version1.8 Updatebeta1
Djangoproject ≫ Django Version1.8.0
Djangoproject ≫ Django Version1.8.1
Djangoproject ≫ Django Version1.8.2
Debian ≫ Debian Linux Version7.0
Debian ≫ Debian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.24% | 0.84 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.