Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-36053

Опубликовано: 03 июл. 2023
Источник: debian
EPSS Низкий

Описание

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed3:3.2.20-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2023/07/03/1

  • https://www.djangoproject.com/weblog/2023/jul/03/security-releases/

  • https://github.com/django/django/commit/ad0410ec4f458aa39803e5f6b9a3736527062dcd (main)

  • https://github.com/django/django/commit/454f2fb93437f98917283336201b4048293f7582 (3.2.20)

EPSS

Процентиль: 86%
0.02994
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
redhat
почти 2 года назад

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

CVSS3: 7.5
nvd
почти 2 года назад

In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

suse-cvrf
почти 2 года назад

Security update for python-Django1

suse-cvrf
почти 2 года назад

Security update for python-Django1

EPSS

Процентиль: 86%
0.02994
Низкий