CVE-2025-48432

Name
CVE-2025-48432
Description
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are viewed in terminals or processed by external systems.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://docs.djangoproject.com/en/dev/releases/security/
cve@mitre.org https://groups.google.com/g/django-announce
cve@mitre.org https://www.djangoproject.com/weblog/2025/jun/04/security-releases/
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/06/04/5
cve@mitre.org https://www.djangoproject.com/weblog/2025/jun/10/bugfix-releases/
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/06/10/2
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/06/10/3
af854a3a-2127-422b-91ae-364da2661108 http://www.openwall.com/lists/oss-security/2025/06/10/4

Match rules

CPE URI Source package Min version Max version
django >= 4.2 < 4.2.23
django >= 5.1 < 5.1.11
django >= 5.2 < 5.2.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-django edge-community 4.2.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
py3-django 3.22-community 4.2.22-r0 None fixed
py3-django 3.21-community 4.2.22-r0 Natanael Copa <ncopa@alpinelinux.org> fixed