Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-296w-6qhq-gf92

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Django denial of service via file upload naming

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.4.14

1.4.14

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.5, < 1.5.9

1.5.9

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.6, < 1.6.6

1.6.6

EPSS

Процентиль: 80%
0.01487
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

ubuntu
почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

redhat
почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

nvd
почти 11 лет назад

The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

debian
почти 11 лет назад

The default configuration for the file upload handling system in Djang ...

EPSS

Процентиль: 80%
0.01487
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400