Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-27351

Опубликовано: 04 мар. 2024
Источник: redhat
CVSS3: 7.5

Описание

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

An inefficient regular expression complexity flaw was found in the Truncator.words function and truncatewords_html filter of Django. This issue may allow an attacker to use a suitably crafted string to cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2ansible-towerNot affected
Red Hat Certification for Red Hat Enterprise Linux 7python-djangoOut of support scope
Red Hat Certification for Red Hat Enterprise Linux 8redhat-certificationAffected
Red Hat Certification for Red Hat Enterprise Linux 9redhat-certificationAffected
Red Hat Discoverydiscovery-server-containerNot affected
Red Hat OpenStack Platform 16.1python-django20Out of support scope
Red Hat OpenStack Platform 16.2python-django20Affected
Red Hat OpenStack Platform 18.0python-djangoAffected
Red Hat Storage 3python-djangoAffected
Red Hat Ansible Automation Platform 2.4 for RHEL 8python3x-djangoFixedRHSA-2024:164002.04.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2266045python-django: Potential regular expression denial-of-service in django.utils.text.Truncator.words()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

CVSS3: 5.3
nvd
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

CVSS3: 5.3
debian
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, ...

suse-cvrf
больше 1 года назад

Security update for python-Django1

suse-cvrf
больше 1 года назад

Security update for python-Django

7.5 High

CVSS3