python2-django vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the python2-django package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2024-45231

*
  • M
Resource Exhaustion

*
  • L
Directory Traversal

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Improper Validation of Specified Type of Input

*
  • L
Information Exposure

*
  • M
Resource Exhaustion

*
  • L
Information Exposure

*
  • L
Directory Traversal

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:1.11.29-1.el7sat
  • H
Directory Traversal

<0:1.11.29-1.el7sat
  • H
Incorrect Default Permissions

<0:1.11.29-1.el7sat
  • H
Improper Validation of Certificate with Host Mismatch

<0:1.11.29-1.el7sat
  • H
Improper Input Validation

<0:1.11.29-1.el7sat
  • H
HTTP Request Smuggling

<0:1.11.29-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.29-1.el7sat
  • H
Eval Injection

<0:1.11.29-1.el7sat
  • H
HTTP Response Splitting

<0:1.11.29-1.el7sat
  • H
Improper Authentication

<0:1.11.29-1.el7sat
  • H
Insufficiently Protected Credentials

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Improper Input Validation

<0:1.11.29-1.el7sat
  • H
Improperly Implemented Security Check for Standard

<0:1.11.29-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.29-1.el7sat
  • H
CVE-2018-3258

<0:1.11.29-1.el7sat
  • H
Missing Authorization

<0:1.11.29-1.el7sat
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
CVE-2024-24680

*
  • M
CVE-2024-24680

*
  • M
Improper Input Validation

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Improper Input Validation

*
  • M
Information Exposure Through Log Files

<0:1.11.13-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.13-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.13-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.13-1.el7sat
  • M
Information Exposure

<0:1.11.29-1.el7sat
  • M
Missing Authorization

<0:1.11.29-1.el7sat
  • M
Information Exposure Through Log Files

<0:1.11.29-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • H
SQL Injection

<0:1.11.11-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.11-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.11-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.11-1.el7sat
  • H
XML External Entity (XXE) Injection

<0:1.11.11-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • H
Improper Input Validation

<0:1.11.29-1.el7sat
  • H
Use of a Broken or Risky Cryptographic Algorithm

<0:1.11.11-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.29-1.el7sat
  • H
Improper Access Control

<0:1.11.11-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.11.11-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.11.11-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • H
Covert Timing Channel

<0:1.11.11-1.el7sat
  • H
Incorrect Calculation

<0:1.11.11-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.11.11-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.11.11-1.el7sat
  • H
Missing Required Cryptographic Step

<0:1.11.11-1.el7sat
  • M
Information Exposure

<0:1.11.29-1.el7sat
  • M
Directory Traversal

<0:1.11.13-1.el7sat
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

<0:1.11.11-1.el7sat
  • H
Improper Certificate Validation

<0:1.11.11-1.el7sat
  • M
Incorrect Permission Assignment for Critical Resource

<0:1.11.13-1.el7sat
  • M
Cleartext Storage of Sensitive Information

<0:1.11.13-1.el7sat
  • M
Improper Authentication

<0:1.11.13-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • H
Improper Authorization

<0:1.11.13-1.el7sat
  • H
Cleartext Transmission of Sensitive Information

<0:1.11.13-1.el7sat
  • H
Improper Certificate Validation

<0:1.11.13-1.el7sat
  • L
Resource Injection

*
  • L
Resource Injection

*
  • L
Resource Injection

*
  • H
Insufficiently Protected Credentials

<0:1.11.29-1.el7sat
  • M
Open Redirect

<0:1.11.15-4.el7rhgs
  • M
Open Redirect

*
  • M
Open Redirect

*
  • H
Improper Input Validation

<0:1.11.11-1.el7sat
  • M
Improper Input Validation

*
  • M
Improper Input Validation

<0:1.11.15-4.el7rhgs
  • M
Improper Input Validation

<0:1.11.15-4.el7rhgs
  • H
Improper Input Validation

<0:1.11.11-1.el7sat
  • M
Improper Input Validation

<0:1.11.11-1.el7ost
  • H
Cross-site Scripting (XSS)

<0:1.11.11-1.el7sat
  • H
Improper Authentication

<0:1.11.29-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.13-1.el7sat
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

<0:1.11.29-1.el7sat
  • H
Information Exposure

<0:1.11.29-1.el7sat
  • H
Information Exposure

<0:1.11.29-1.el7sat
  • H
Incorrect Default Permissions

<0:1.11.29-1.el7sat
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • L
SQL Injection

*
  • M
SQL Injection

*
  • M
SQL Injection

<0:1.11.29-1.el7sat
  • L
SQL Injection

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

<0:1.11.27-1.el7ost
  • M
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

<0:1.11.27-1.el7ost
  • M
Improper Input Validation

*
  • M
Improper Input Validation

<0:1.11.27-1.el7ost
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

<0:1.11.27-1.el7ost
  • M
Improper Input Validation

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
Improperly Implemented Security Check for Standard

*
  • H
Improperly Implemented Security Check for Standard

<0:1.11.29-1.el7sat
  • M
Improperly Implemented Security Check for Standard

<0:1.11.27-1.el7ost
  • M
Incorrect Default Permissions

*
  • M
Incorrect Default Permissions

*
  • L
SQL Injection

*
  • L
SQL Injection

*
  • L
SQL Injection

*
  • M
Improper Authorization

*
  • M
Incorrect Default Permissions

*
  • M
Incorrect Default Permissions

*
  • M
Improper Input Validation

<0:1.11.27-3.el7ost
  • M
Improper Input Validation

*
  • L
Improper Input Validation

*
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • H
SQL Injection

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • L
Directory Traversal

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

<0:1.11.11-1.el7sat
  • H
Missing Authorization

<0:1.11.29-1.el7sat
  • H
Information Exposure

<0:1.11.11-1.el7sat
  • M
SQL Injection

*
  • H
Improper Validation of Certificate with Host Mismatch

<0:1.11.29-1.el7sat
  • M
SQL Injection

*
  • M
Execution with Unnecessary Privileges

<0:1.11.29-1.el7sat
  • H
HTTP Request Smuggling

<0:1.11.29-1.el7sat
  • M
Resource Exhaustion

<0:1.11.13-1.el7sat
  • M
Out-of-Bounds

<0:1.11.29-1.el7sat
  • M
Information Exposure

<0:1.11.29-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:1.11.29-1.el7sat
  • H
Cross-site Scripting (XSS)

<0:1.11.29-1.el7sat
  • M
Cross-site Request Forgery (CSRF)

<0:1.11.29-1.el7sat
  • H
Improper Input Validation

<0:1.11.29-1.el7sat
  • M
Cross-site Scripting (XSS)

<0:1.11.29-1.el7sat
  • M
Improper Input Validation

<0:1.11.29-1.el7sat
  • M
Improper Input Validation

<0:1.11.29-1.el7sat
  • H
Eval Injection

<0:1.11.29-1.el7sat
  • H
Directory Traversal

<0:1.11.29-1.el7sat
  • H
HTTP Response Splitting

<0:1.11.29-1.el7sat
  • H
Incomplete Blacklist

<0:1.11.11-1.el7sat
  • H
Reliance on Untrusted Inputs in a Security Decision

<0:1.11.29-1.el7sat
  • L
HTTP Request Smuggling

*
  • M
HTTP Request Smuggling

*
  • M
HTTP Response Splitting

<0:1.11.13-1.el7sat
  • H
CVE-2018-3258

<0:1.11.29-1.el7sat
  • M
Covert Timing Channel

<0:1.11.29-1.el7sat
  • H
Covert Timing Channel

<0:1.11.29-1.el7sat
  • H
Covert Timing Channel

<0:1.11.29-1.el7sat
  • M
Arbitrary Argument Injection

<0:1.11.13-1.el7sat
  • H
Out-of-Bounds

<0:1.11.11-1.el7sat
  • M
Improper Neutralization of Special Elements

<0:1.11.13-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.13-1.el7sat
  • M
CVE-2016-6346

<0:1.11.13-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • M
Improper Neutralization of Special Elements

<0:1.11.13-1.el7sat
  • M
Information Exposure

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.29-1.el7sat
  • M
Use After Free

<0:1.11.29-1.el7sat
  • H
Deserialization of Untrusted Data

<0:1.11.13-1.el7sat