The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-django | Jul 30, 2024 | Apr 23, 2014 |
| Freebsd | — | Upgrade py34-djangoUpgrade py34-django15Upgrade py32-djangoUpgrade py31-djangoUpgrade py33-django15Upgrade py31-django14Upgrade py33-djangoUpgrade py27-django14Upgrade py33-django14Upgrade py31-django15Upgrade py26-djangoUpgrade py27-django-develUpgrade py32-django14Upgrade py27-djangoUpgrade py34-django14Upgrade py26-django14Upgrade py26-django-develUpgrade py32-django15Upgrade py27-django15Upgrade py26-django15 | Dec 10, 2025 | Apr 23, 2014 |
| Gentoo Linux | — | Upgrade dev-python/django. | Oct 30, 2017 | Apr 23, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Apr 23, 2014 |
| Suse | — | Upgrade python-django | Dec 18, 2015 | Apr 23, 2014 |
| Ubuntu | — | Upgrade python-django | Nov 8, 2024 | Apr 23, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub