V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
BDU:2019-03594
BDU
CriticalConfirmedExploit available

Уязвимость функций django.contrib.postgres.fields.HStoreField и django.contrib.postgres.fields.JSONField фреймворка для веб-разработки Djan…

CVSS
9.8
Critical
EPSS
0.00
p0
Published
2019-01-01
Updated
2019-01-01
Description

Уязвимость функций django.contrib.postgres.fields.HStoreField и django.contrib.postgres.fields.JSONField фреймворка для веб-разработки Django связана с ошибкой преобразовании и поиска ключей, а так же поиска индексов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, оказать воздействие на целостность данных, получить несанкционированный доступ к защищаемой информации, а также вызвать отказ в обслуживании

Tags · CWE
Pre-auth
Affected products
Django software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation DjangoDjango software foundation Django
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2019-14234
github-poc · https://github.com/malvika-thakur/CVE-2019-14234
Enterprise
Affected products
ProductVendorStatus
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
djangodjango software foundationTracked
Showing first 20 of 70