Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-39317

Опубликовано: 11 июл. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 4.9
EPSS Низкий

Описание

Wagtail is an open source content management system built on Django. A bug in Wagtail's parse_query_string would result in it taking a long time to process suitably crafted inputs. When used to parse sufficiently long strings of characters without a space, parse_query_string would take an unexpectedly large amount of time to process, resulting in a denial of service. In an initial Wagtail installation, the vulnerability can be exploited by any Wagtail admin user. It cannot be exploited by end users. If your Wagtail site has a custom search implementation which uses parse_query_string, it may be exploitable by other users (e.g. unauthenticated users). Patched versions have been released as Wagtail 5.2.6, 6.0.6 and 6.1.3.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wagtail:wagtail:*:*:*:*:*:*:*:*
Версия от 2.0 (включая) до 5.2.6 (исключая)
cpe:2.3:a:wagtail:wagtail:*:*:*:*:*:*:*:*
Версия от 6.0 (включая) до 6.0.6 (исключая)
cpe:2.3:a:wagtail:wagtail:*:*:*:*:*:*:*:*
Версия от 6.1 (включая) до 6.1.3 (исключая)

EPSS

Процентиль: 55%
0.00329
Низкий

6.5 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-1333
CWE-1333

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

Wagtail regular expression denial-of-service via search query parsing

EPSS

Процентиль: 55%
0.00329
Низкий

6.5 Medium

CVSS3

4.9 Medium

CVSS3

Дефекты

CWE-1333
CWE-1333