Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-56374

Опубликовано: 14 янв. 2025
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-djangofixed3:4.2.18-1package

Примечания

  • https://www.djangoproject.com/weblog/2025/jan/14/security-releases/

  • Fixed by: https://github.com/django/django/commit/ad866a1ca3e7d60da888d25d27e46a8adb2ed36e (4.2.18)

EPSS

Процентиль: 18%
0.00056
Низкий

Связанные уязвимости

CVSS3: 5.8
ubuntu
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
redhat
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
nvd
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

suse-cvrf
5 месяцев назад

Security update for python-Django

CVSS3: 5.8
github
5 месяцев назад

Django has a potential denial-of-service vulnerability in IPv6 validation

EPSS

Процентиль: 18%
0.00056
Низкий