← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-0474

The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:4.75%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
canonical ubuntu_linux 10.04, 12.04, 12.10, 13.10, 14.04
djangoproject django 1.6, 1.6.1, 1.6.2, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.7, 1.5, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.753%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDebian GNU/Linux · Vendor · USA
Reserved2013-12-19T00:00:00
Published2014-04-23T14:00:00
Patch Date2014-04-21
Last Updated2024-08-06T09:20:18

LINK COPIED TO CLIPBOARD