Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jqw-crqj-w8qw

Опубликовано: 23 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Denial of service in django

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

< 1.2.7

1.2.7

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.3, < 1.3.1

1.3.1

EPSS

Процентиль: 82%
0.01736
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1088

Связанные уязвимости

ubuntu
больше 13 лет назад

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.

nvd
больше 13 лет назад

The verify_exists functionality in the URLField implementation in Django before 1.2.7 and 1.3.x before 1.3.1 relies on Python libraries that attempt access to an arbitrary URL with no timeout, which allows remote attackers to cause a denial of service (resource consumption) via a URL associated with (1) a slow response, (2) a completed TCP connection with no application data sent, or (3) a large amount of application data, a related issue to CVE-2011-1521.

debian
больше 13 лет назад

The verify_exists functionality in the URLField implementation in Djan ...

EPSS

Процентиль: 82%
0.01736
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1088