Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53907

Опубликовано: 04 дек. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

A vulnerability was found in the Django Web Framework. The strip_tags() and stripbtags template filter may be vulnerable to a potential denial of service (DoS) in cases of a large sequence of nested incomplete HTML entities.

Отчет

This vulnerability is rated as a Moderate severity because it exposes the strip_tags() method and striptags template filter to a potential denial-of-service attack, malicious input containing large sequences of nested incomplete HTML entities could cause excessive processing, but it does not affect data confidentiality or integrity

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2python-djangoAffected
Discovery 1 for RHEL 9discovery/discovery-server-rhel9FixedRHSA-2025:124910.02.2025
Discovery 1 for RHEL 9discovery/discovery-ui-rhel9FixedRHSA-2025:124910.02.2025
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-cloud-billing-rhel8FixedRHSA-2024:1114416.12.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-cloud-billing-rhel8-operatorFixedRHSA-2024:1114416.12.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-cloud-metrics-collector-rhel8FixedRHSA-2024:1114416.12.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-cloud-ui-rhel8FixedRHSA-2024:1114416.12.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-cloud-ui-rhel8-operatorFixedRHSA-2024:1114416.12.2024
Red Hat Ansible Automation Platform 2.4 for RHEL 8ansible-automation-platform-24/aap-must-gather-rhel8FixedRHSA-2024:1114416.12.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1169
https://bugzilla.redhat.com/show_bug.cgi?id=2329288django: Potential denial-of-service in django.utils.html.strip_tags()

EPSS

Процентиль: 27%
0.00092
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 7.5
nvd
6 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested incomplete HTML entities.

CVSS3: 7.5
debian
6 месяцев назад

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, ...

CVSS3: 7.5
github
6 месяцев назад

Django denial-of-service in django.utils.html.strip_tags()

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость функции strip_tags() модуля django.utils.html программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00092
Низкий

6.5 Medium

CVSS3