Описание
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
A vulnerability was found in Python-Django in the get_supported_language_variant() function. The issue triggers when parsed with very long strings, including a specific set of characters, leading to a potential denial of service attack.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | ansible-tower | Will not fix | ||
Red Hat Certification for Red Hat Enterprise Linux 7 | python-django | Affected | ||
Red Hat Certification for Red Hat Enterprise Linux 8 | redhat-certification | Affected | ||
Red Hat Certification for Red Hat Enterprise Linux 9 | redhat-certification | Affected | ||
Red Hat Discovery | discovery-server-container | Affected | ||
Red Hat OpenStack Platform 16.1 | python-django20 | Affected | ||
Red Hat OpenStack Platform 16.2 | python-django20 | Affected | ||
Red Hat OpenStack Platform 17.1 | python-django | Will not fix | ||
Red Hat Storage 3 | python-django | Affected | ||
Red Hat Ansible Automation Platform 2.4 for RHEL 8 | ansible-automation-platform-24/lightspeed-rhel8 | Fixed | RHBA-2024:6429 | 05.09.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2. ...
Уязвимость функции get_supported_language_variant() программной платформы для веб-приложений Django, связанная с ошибками при обработке параметров длины, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.3 Medium
CVSS3