VDB
CVE-2022-22818
CVE-2022-22818
PUBLISHED
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
EPSS 0.55% · 68.5th percentile
Risk Scores
EPSS Score
0.55%
68.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | django | 4.0.0, 4.0.0, 2.2.0 |
| Bitnami | django | 3.2.0, 2.2.0, 4.0.0 |
Exploit Intelligence
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
- This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818) (github-poc-repo)
…and 11 more exploits
Timeline
- Feb 3, 2022 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 11, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 27, 2023 EPSS Score
References
- https://docs.djangoproject.com/en/4.0/releases/security/ url
- https://groups.google.com/forum/#%21forum/django-announce url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4SQG2EAF4WCI2SLRL6XRDJ3RPK3ZRDV/ url
- https://security.netapp.com/advisory/ntap-20220221-0003/ url
- https://www.debian.org/security/2022/dsa-5254 url
- https://www.djangoproject.com/weblog/2022/feb/01/security-releases/ url
- https://nvd.nist.gov/vuln/detail/CVE-2022-22818 url