Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3fp-8748-vqfq

Опубликовано: 06 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Django vulnerable to Allocation of Resources Without Limits or Throttling

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.20

4.2.20

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.0.13

5.0.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.1, < 5.1.7

5.1.7

EPSS

Процентиль: 80%
0.01394
Низкий

5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5
ubuntu
11 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
redhat
11 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
nvd
11 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
debian
11 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

suse-cvrf
11 месяцев назад

Security update for python-Django

EPSS

Процентиль: 80%
0.01394
Низкий

5 Medium

CVSS3

Дефекты

CWE-770