Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h8gc-pgj2-vjm3

Опубликовано: 03 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 5.9

Описание

Django Denial-of-service in django.utils.text.Truncator

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 3.2a1, < 3.2.22

3.2.22

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.1a1, < 4.1.12

4.1.12

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2a1, < 4.2.6

4.2.6

EPSS

Процентиль: 84%
0.0219
Низкий

8.7 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-1284
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.

CVSS3: 7.5
redhat
больше 1 года назад

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.

CVSS3: 7.5
nvd
больше 1 года назад

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.

CVSS3: 7.5
debian
больше 1 года назад

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, ...

suse-cvrf
больше 1 года назад

Security update for python-Django1

EPSS

Процентиль: 84%
0.0219
Низкий

8.7 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-1284
CWE-400