Django: 1.6.11 → 1.11.29
Django · upgrade impact · Official site ↗
Fixed by upgrading to 1.11.29 iVulnerabilities that affect 1.6.11 but no longer affect 1.11.29 — the security gain from this upgrade, by exploited status then exploitation probability.
Exploited first, then by exploitation probability (EPSS).
CVE-2016-6186 MEDIUM EPSS 16% ✓ cleared in 1.11.29 CVE-2019-19844 CRITICAL EPSS 15% ✓ cleared in 1.11.29 CVE-2016-7401 HIGH EPSS 6% ✓ cleared in 1.11.29 CVE-2015-8213 MEDIUM EPSS 3% ✓ cleared in 1.11.29 CVE-2015-2241 MEDIUM EPSS 0% ✓ cleared in 1.11.29Still open in 1.11.29 iKnown vulnerabilities that affect 1.11.29 too — upgrading to it does not clear these.
These affect 1.11.29 as well — a later release may be needed.
CVE-2021-33203 MEDIUM EPSS 0% → fixed in 3.2.4