Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3fp-8748-vqfq

Опубликовано: 06 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Django vulnerable to Allocation of Resources Without Limits or Throttling

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.20

4.2.20

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.0.13

5.0.13

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.1, < 5.1.7

5.1.7

EPSS

Процентиль: 37%
0.00158
Низкий

5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5
ubuntu
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 7.5
redhat
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
nvd
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.

CVSS3: 5
debian
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, ...

suse-cvrf
5 месяцев назад

Security update for python-Django

EPSS

Процентиль: 37%
0.00158
Низкий

5 Medium

CVSS3

Дефекты

CWE-770