Vulnerabilities
Vulnerable Software
Djangoproject:  >> Django  >> 5.0.2  Security Vulnerabilities
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a save() call. (Built-in Storage sub-classes are unaffected.)
CVSS Score
4.3
EPSS Score
0.001
Published
2024-07-10
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
CVSS Score
7.5
EPSS Score
0.024
Published
2024-07-10


Contact Us

Shodan ® - All rights reserved