Log Manipulation Vulnerability in Django Products by Django Software Foundation
CVE-2025-48432

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 June 2025

What is CVE-2025-48432?

A vulnerability has been identified in Django, impacting versions prior to 5.2.2, 5.1.10, and 4.2.22. The issue lies in the internal HTTP response logging, where the 'request.path' is not properly escaped. This oversight allows attackers to craft malicious URLs, potentially leading to log manipulation practices, such as log injection or forgery. When logs are viewed in various contexts, including terminals or processed by external systems, the integrity of the logs can be compromised, posing risks to the application’s security and reliability.

Affected Version(s)

Django 4.2 < 4.2.22

Django 5.1 < 5.1.10

Django 5.2 < 5.2.2

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48432 : Log Manipulation Vulnerability in Django Products by Django Software Foundation