Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9v8h-57gv-qch6

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Django vulnerable to Denial of Service via i18n middleware component

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

= 0.96.0

0.96.1

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 0.95, < 0.95.2

0.95.2

Наименование

Django

pip
Затронутые версииВерсия исправления

= 0.91.0

0.91.1

EPSS

Процентиль: 81%
0.01594
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

ubuntu
больше 17 лет назад

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

nvd
больше 17 лет назад

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

debian
больше 17 лет назад

The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1 ...

EPSS

Процентиль: 81%
0.01594
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-400