Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6m5-h7pp-v2x5

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Django Regex Algorithmic Complexity Causes Denial of Service

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.0, < 1.0.4

1.0.4

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 1.1, < 1.1.1

1.1.1

EPSS

Процентиль: 76%
0.01012
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400

Связанные уязвимости

ubuntu
больше 15 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

nvd
больше 15 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of backtracking in a regular expression.

debian
больше 15 лет назад

Algorithmic complexity vulnerability in the forms library in Django 1. ...

EPSS

Процентиль: 76%
0.01012
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-400