Djangoproject

Django

128 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.2%
  • Veröffentlicht 09.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:19

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expr...

  • EPSS 1.2%
  • Veröffentlicht 09.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:19

An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due t...

  • EPSS 0.7%
  • Veröffentlicht 05.02.2018 03:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:15

django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated b...

  • EPSS 18.77%
  • Veröffentlicht 07.09.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shoul...

  • EPSS 0.75%
  • Veröffentlicht 04.04.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some nu...

  • EPSS 0.42%
  • Veröffentlicht 04.04.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

  • EPSS 4.31%
  • Veröffentlicht 09.12.2016 20:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOS...

  • EPSS 2.4%
  • Veröffentlicht 09.12.2016 20:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the da...

  • EPSS 5.49%
  • Veröffentlicht 03.10.2016 18:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

  • EPSS 13.1%
  • Veröffentlicht 05.08.2016 15:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to ...