The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade django-cms to version 5.0.8 or higher.
Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information via the get_vary_cache_on process. An attacker can cause sensitive information to be disclosed to other users and manipulate cached content by priming the cache with attacker-controlled header values. This is only exploitable if CMS_PAGE_CACHE is enabled and at least one plugin implements get_vary_cache_on().
This vulnerability can be mitigated by disabling CMS_PAGE_CACHE or avoiding plugins that rely on get_vary_cache_on().