Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcgg-j2x8-h9g8

Опубликовано: 14 янв. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.8

Описание

Django has a potential denial-of-service vulnerability in IPv6 validation

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

Пакеты

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.1, < 5.1.5

5.1.5

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.0.11

5.0.11

Наименование

Django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.18

4.2.18

Наименование

django

pip
Затронутые версииВерсия исправления

>= 5.1, < 5.1.5

5.1.5

Наименование

django

pip
Затронутые версииВерсия исправления

>= 5.0, < 5.0.11

5.0.11

Наименование

django

pip
Затронутые версииВерсия исправления

>= 4.2, < 4.2.18

4.2.18

EPSS

Процентиль: 18%
0.00056
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.8
ubuntu
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
redhat
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
nvd
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
debian
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, ...

suse-cvrf
5 месяцев назад

Security update for python-Django

EPSS

Процентиль: 18%
0.00056
Низкий

5.8 Medium

CVSS3

Дефекты

CWE-770