Search CVE reports


Toggle filters

51 – 60 of 139 results


CVE-2020-17495

Medium priority
Needs evaluation

django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted...

1 affected package

python-django-celery-results

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django-celery-results Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-13596

Medium priority
Fixed

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed
Show less packages

CVE-2020-13254

Medium priority
Fixed

An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed
Show less packages

CVE-2020-9402

Medium priority
Fixed

Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed
Show less packages

CVE-2020-7471

Medium priority
Fixed

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed
Show less packages

CVE-2019-19844

High priority
Fixed

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed
Show less packages

CVE-2019-19118

Medium priority
Not affected

Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Not affected
Show less packages

CVE-2013-4409

Medium priority
Ignored

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

2 affected packages

djblets, python-django-djblets

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
djblets
python-django-djblets
Show less packages

CVE-2019-14235

Medium priority

Some fixes available 11 of 12

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
Show less packages

CVE-2019-14234

Medium priority

Some fixes available 11 of 12

An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key...

1 affected package

python-django

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed
Show less packages