CVE-2015-5144

Description

Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
2.238

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-5143,CVE-2015-5144 are fixed in Python-django 1.4.21Windows
Vulnerabilities CVE-2015-5143,CVE-2015-5144 are fixed in Python-django 1.7.9Windows
Vulnerabilities CVE-2015-5143,CVE-2015-5144,CVE-2015-5145 are fixed in Python-django 1.8.3Windows
High-level Python web development framework (USN-2671-1) python-django_1.7.6-1ubuntu2.3_all.debLinux
High-level Python web development framework (USN-2671-1) python3-django_1.7.6-1ubuntu2.3_all.debLinux
Vulnerabilities CVE-2015-5143,CVE-2015-5144 are fixed in Python-django for linux 1.4.21Linux
Vulnerabilities CVE-2015-5143,CVE-2015-5144 are fixed in Python-django for linux 1.7.9Linux
Vulnerabilities CVE-2015-5143,CVE-2015-5144,CVE-2015-5145 are fixed in Python-django for linux 1.8.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234