VDB

CVE-2015-5144

CVE-2015-5144 PUBLISHED

Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an (1) email message to the EmailValidator, a (2) URL to the URLValidator, or unspecified vectors to the (3) validate_ipv4_address or (4) validate_slug validator.

EPSS 3.66% · 89.2th percentile

Risk Scores

EPSS Score
3.66%
89.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpython-django0, 1.5.4-1ubuntu1, 1.6-1

Timeline

  • Jul 8, 2015 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 4, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
  • Nov 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›