Vulnerability Intelligence Report
CVE-2014-0474
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote attackers to have unspecified impact and vectors, related to "MySQL typecasting."
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:4.75%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| canonical | ubuntu_linux | 10.04, 12.04, 12.10, 13.10, 14.04 |
| djangoproject | django | 1.6, 1.6.1, 1.6.2, 1.4, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.7, 1.5, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.5.5 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.753%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Debian GNU/Linux · Vendor · USA |
| Reserved | 2013-12-19T00:00:00 |
| Published | 2014-04-23T14:00:00 |
| Patch Date | 2014-04-21 |
| Last Updated | 2024-08-06T09:20:18 |
Community Chatter & Buzz