Описание
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.
Релиз | Статус | Примечание |
---|---|---|
artful | released | 1:1.11.4-1ubuntu1.2 |
devel | released | 1:1.11.11-1ubuntu1 |
esm-infra-legacy/trusty | not-affected | 1.6.11-0ubuntu1.2 |
esm-infra/xenial | not-affected | 1.8.7-1ubuntu5.6 |
precise/esm | DNE | |
trusty | released | 1.6.11-0ubuntu1.2 |
trusty/esm | not-affected | 1.6.11-0ubuntu1.2 |
upstream | released | 1.8.19,1.11.11 |
xenial | released | 1.8.7-1ubuntu5.6 |
Показывать по
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.
An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.1 ...
Django Denial-of-service possibility in truncatechars_html and truncatewords_html template filters
Уязвимость функции django.utils.html.urlize и методов chars и words объектов django.utils.text.Truncator программной платформы для веб-приложений Django, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2
5.3 Medium
CVSS3