Python/django/5.1


A high-level Python web framework that encourages rapid development and clean, pragmatic design.

https://pypi.org/project/django
BSD-3-Clause AND BSD

2 Security Vulnerabilities

Django denial-of-service in django.utils.html.strip_tags()

Published date: 2024-12-06T12:30:47Z
CVE: CVE-2024-53907
Links:

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

Affected versions: ["4.2", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.2.11", "4.2.12", "4.2.13", "4.2.14", "4.2.15", "4.2.16", "5.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.1", "5.1.1", "5.1.2", "5.1.3"]
Secure versions: [2.2.27, 2.2.28, 3.0a1, 3.1.12, 3.1.13, 3.1.14, 3.2.25, 4.1.13, 4.2.17, 4.2.18, 4.2.19, 4.2.20, 4.2.21, 4.2.22, 4.2.23, 4.2a1, 4.2b1, 4.2rc1, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0a1, 5.0b1, 5.0rc1, 5.1.10, 5.1.11, 5.1.4, 5.1.5, 5.1.6, 5.1.7, 5.1.8, 5.1.9, 5.1a1, 5.1b1, 5.1rc1, 5.2, 5.2.1, 5.2.2, 5.2.3, 5.2a1, 5.2b1, 5.2rc1]
Recommendation: Update to version 5.2.3.

Django SQL injection in HasKey(lhs, rhs) on Oracle

Published date: 2024-12-06T12:30:47Z
CVE: CVE-2024-53908
Links:

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subject to SQL injection if untrusted data is used as an lhs value. (Applications that use the jsonfield.haskey lookup via _ are unaffected.)

Affected versions: ["4.2", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.2.11", "4.2.12", "4.2.13", "4.2.14", "4.2.15", "4.2.16", "5.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.1", "5.1.1", "5.1.2", "5.1.3"]
Secure versions: [2.2.27, 2.2.28, 3.0a1, 3.1.12, 3.1.13, 3.1.14, 3.2.25, 4.1.13, 4.2.17, 4.2.18, 4.2.19, 4.2.20, 4.2.21, 4.2.22, 4.2.23, 4.2a1, 4.2b1, 4.2rc1, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0a1, 5.0b1, 5.0rc1, 5.1.10, 5.1.11, 5.1.4, 5.1.5, 5.1.6, 5.1.7, 5.1.8, 5.1.9, 5.1a1, 5.1b1, 5.1rc1, 5.2, 5.2.1, 5.2.2, 5.2.3, 5.2a1, 5.2b1, 5.2rc1]
Recommendation: Update to version 5.2.3.

400 Other Versions

Version License Security Released
5.2.3 BSD-3-Clause AND BSD
5.2.2 BSD-3-Clause AND BSD
5.2.1 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.2 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.11 BSD-3-Clause AND BSD
5.1.10 BSD-3-Clause AND BSD
5.1.9 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.8 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.7 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.6 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.5 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.4 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.1.3 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.1.2 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.1.1 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.1 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.14 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.0.13 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.0.12 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.0.11 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.0.10 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
5.0.9 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.8 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.7 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.6 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.5 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.4 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.3 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
5.0.2 BSD-3-Clause AND BSD 3 1970-01-01 - 00:00 over 55 years
5.0.1 BSD-3-Clause AND BSD 4 1970-01-01 - 00:00 over 55 years
5.0 BSD-3-Clause AND BSD 4 1970-01-01 - 00:00 over 55 years
4.2.23 BSD-3-Clause AND BSD
4.2.22 BSD-3-Clause AND BSD
4.2.21 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
4.2.20 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
4.2.19 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
4.2.18 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
4.2.17 BSD-3-Clause AND BSD 1970-01-01 - 00:00 over 55 years
4.2.16 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.15 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.14 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.13 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.12 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.11 BSD-3-Clause AND BSD 2 1970-01-01 - 00:00 over 55 years
4.2.10 BSD-3-Clause AND BSD 3 1970-01-01 - 00:00 over 55 years
4.2.9 BSD-3-Clause AND BSD 4 1970-01-01 - 00:00 over 55 years
4.2.8 BSD-3-Clause AND BSD 4 1970-01-01 - 00:00 over 55 years
4.2.7 BSD-3-Clause AND BSD 4 1970-01-01 - 00:00 over 55 years
4.2.6 BSD-3-Clause AND BSD 5 1970-01-01 - 00:00 over 55 years
4.2.5 BSD-3-Clause AND BSD 6 1970-01-01 - 00:00 over 55 years