Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3fp-8748-vqfq

Опубликовано: 06 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Django vulnerable to Allocation of Resources Without Limits or Throttling

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.20

4.2.20

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.0.13

5.0.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.1, < 5.1.7

5.1.7

EPSS

Процентиль: 52%
0.00766
Низкий

5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
redhat
больше 1 года назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
nvd
больше 1 года назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
debian
больше 1 года назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

suse-cvrf
больше 1 года назад

Security update for python-Django

EPSS

Процентиль: 52%
0.00766
Низкий

5 Medium

CVSS3

Дефекты

CWE-770