Python/django/5.0.1
A high-level Python web framework that encourages rapid development and clean, pragmatic design.
https://pypi.org/project/django
BSD-3-Clause
AND
BSD
4 Security Vulnerabilities
Django denial-of-service in django.utils.html.strip_tags()
- https://nvd.nist.gov/vuln/detail/CVE-2024-53907
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.openwall.com/lists/oss-security/2024/12/04/3
- https://www.djangoproject.com/weblog/2024/dec/04/security-releases
- https://lists.debian.org/debian-lts-announce/2024/12/msg00028.html
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-156.yaml
- https://github.com/advisories/GHSA-8498-2h75-472j
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.
Django SQL injection in HasKey(lhs, rhs) on Oracle
- https://nvd.nist.gov/vuln/detail/CVE-2024-53908
- https://docs.djangoproject.com/en/dev/releases/security
- https://groups.google.com/g/django-announce
- https://www.openwall.com/lists/oss-security/2024/12/04/3
- https://www.djangoproject.com/weblog/2024/dec/04/security-releases
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-157.yaml
- https://github.com/advisories/GHSA-m9g8-fxxm-xg86
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.haskey lookup via _ are unaffected.)
Regular expression denial-of-service in Django
- https://nvd.nist.gov/vuln/detail/CVE-2024-27351
- https://docs.djangoproject.com/en/5.0/releases/security
- https://groups.google.com/forum/#%21forum/django-announce
- https://www.djangoproject.com/weblog/2024/mar/04/security-releases
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-47.yaml
- https://github.com/advisories/GHSA-vm8q-m57g-pff3
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2JIRXEDP4ZET5KFMAPPYSK663Q52NEX
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SN2PLJGYSAAG5KUVIUFJYKD3BLQ4OSN6
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D
- http://www.openwall.com/lists/oss-security/2024/03/04/1
- https://github.com/django/django/commit/072963e4c4d0b3a7a8c5412bc0c7d27d1a9c3521
- https://github.com/django/django/commit/3394fc6132436eca89e997083bae9985fb7e761e
- https://github.com/django/django/commit/3c9a2771cc80821e041b16eb36c1c37af5349d4a
In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.
Django denial-of-service attack in the intcomma template filter
- https://nvd.nist.gov/vuln/detail/CVE-2024-24680
- https://docs.djangoproject.com/en/5.0/releases/security/
- https://groups.google.com/forum/#%21forum/django-announce
- https://www.djangoproject.com/weblog/2024/feb/06/security-releases/
- https://github.com/django/django/commit/16a8fe18a3b81250f4fa57e3f93f0599dc4895bc
- https://github.com/django/django/commit/55519d6cf8998fe4c8f5c8abffc2b10a7c3d14e9
- https://github.com/django/django/commit/572ea07e84b38ea8de0551f4b4eda685d91d09d2
- https://github.com/django/django/commit/c1171ffbd570db90ca206c30f8e2b9f691243820
- https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-28.yaml
- https://github.com/advisories/GHSA-xxj9-f6rv-m3x4
- https://docs.djangoproject.com/en/5.0/releases/security
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2JIRXEDP4ZET5KFMAPPYSK663Q52NEX
- https://www.djangoproject.com/weblog/2024/feb/06/security-releases
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SN2PLJGYSAAG5KUVIUFJYKD3BLQ4OSN6
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D
An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.
400 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
4.2.4 | BSD-3-Clause AND BSD | 7 | 1970-01-01 - 00:00 | over 55 years |
4.2.3 | BSD-3-Clause AND BSD | 7 | 1970-01-01 - 00:00 | over 55 years |
4.2.2 | BSD-3-Clause AND BSD | 8 | 1970-01-01 - 00:00 | over 55 years |
4.2.1 | BSD-3-Clause AND BSD | 8 | 1970-01-01 - 00:00 | over 55 years |
4.2 | BSD-3-Clause AND BSD | 8 | 1970-01-01 - 00:00 | over 55 years |
4.1.13 | BSD-3-Clause AND BSD | 1970-01-01 - 00:00 | over 55 years | |
4.1.12 | BSD-3-Clause AND BSD | 1 | 1970-01-01 - 00:00 | over 55 years |
4.1.11 | BSD-3-Clause AND BSD | 2 | 1970-01-01 - 00:00 | over 55 years |
4.1.10 | BSD-3-Clause AND BSD | 3 | 1970-01-01 - 00:00 | over 55 years |
4.1.9 | BSD-3-Clause AND BSD | 4 | 1970-01-01 - 00:00 | over 55 years |
4.1.8 | BSD-3-Clause AND BSD | 4 | 1970-01-01 - 00:00 | over 55 years |
4.1.7 | BSD-3-Clause AND BSD | 4 | 1970-01-01 - 00:00 | over 55 years |
4.1.6 | BSD-3-Clause AND BSD | 4 | 1970-01-01 - 00:00 | over 55 years |
4.1.5 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
4.1.4 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
4.1.3 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
4.1.2 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
4.1.1 | BSD-3-Clause AND BSD | 6 | 1970-01-01 - 00:00 | over 55 years |
4.1 | BSD-3-Clause AND BSD | 6 | 1970-01-01 - 00:00 | over 55 years |
4.0.10 | BSD-3-Clause AND BSD | 1 | 1970-01-01 - 00:00 | over 55 years |
4.0.9 | BSD-3-Clause AND BSD | 1 | 1970-01-01 - 00:00 | over 55 years |
4.0.8 | BSD-3-Clause AND BSD | 2 | 1970-01-01 - 00:00 | over 55 years |
4.0.7 | BSD-3-Clause AND BSD | 3 | 1970-01-01 - 00:00 | over 55 years |
4.0.6 | BSD-3-Clause AND BSD | 3 | 2022-07-04 - 07:57 | almost 3 years |
4.0.5 | BSD-3-Clause AND BSD | 4 | 2022-06-01 - 12:22 | about 3 years |
4.0.4 | BSD-3-Clause AND BSD | 4 | 2022-04-11 - 07:53 | about 3 years |
4.0.3 | BSD-3-Clause AND BSD | 4 | 2022-03-01 - 08:47 | over 3 years |
4.0.2 | BSD-3-Clause AND BSD | 4 | 2022-02-01 - 07:56 | over 3 years |
4.0.1 | BSD-3-Clause AND BSD | 6 | 2022-01-04 - 09:53 | over 3 years |
4.0 | BSD-3-Clause AND BSD | 6 | 2021-12-07 - 09:19 | over 3 years |
3.2.25 | BSD-3-Clause AND BSD | 1970-01-01 - 00:00 | over 55 years | |
3.2.24 | BSD-3-Clause AND BSD | 1 | 1970-01-01 - 00:00 | over 55 years |
3.2.23 | BSD-3-Clause AND BSD | 1 | 1970-01-01 - 00:00 | over 55 years |
3.2.22 | BSD-3-Clause AND BSD | 2 | 1970-01-01 - 00:00 | over 55 years |
3.2.21 | BSD-3-Clause AND BSD | 3 | 1970-01-01 - 00:00 | over 55 years |
3.2.20 | BSD-3-Clause AND BSD | 4 | 1970-01-01 - 00:00 | over 55 years |
3.2.19 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
3.2.18 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
3.2.17 | BSD-3-Clause AND BSD | 5 | 1970-01-01 - 00:00 | over 55 years |
3.2.16 | BSD-3-Clause AND BSD | 6 | 1970-01-01 - 00:00 | over 55 years |
3.2.15 | BSD-3-Clause AND BSD | 7 | 1970-01-01 - 00:00 | over 55 years |
3.2.14 | BSD-3-Clause AND BSD | 7 | 2022-07-04 - 07:57 | almost 3 years |
3.2.13 | BSD-3-Clause AND BSD | 8 | 2022-04-11 - 07:52 | about 3 years |
3.2.12 | BSD-3-Clause AND BSD | 8 | 2022-02-01 - 07:56 | over 3 years |
3.2.11 | BSD-3-Clause AND BSD | 10 | 2022-01-04 - 09:53 | over 3 years |
3.2.10 | BSD-3-Clause AND BSD | 10 | 2021-12-07 - 07:34 | over 3 years |
3.2.9 | BSD-3-Clause AND BSD | 10 | 2021-11-01 - 09:31 | over 3 years |
3.2.8 | BSD-3-Clause AND BSD | 10 | 2021-10-05 - 07:46 | over 3 years |
3.2.7 | BSD-3-Clause AND BSD | 10 | 2021-09-01 - 05:57 | almost 4 years |
3.2.6 | BSD-3-Clause AND BSD | 10 | 2021-08-02 - 06:28 | almost 4 years |