Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-27351

Опубликовано: 15 мар. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

3:4.2.11-1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

released

1:1.11.11-1ubuntu1.21+esm4
esm-infra/focal

not-affected

2:2.2.12-1ubuntu0.22
esm-infra/xenial

needs-triage

focal

released

2:2.2.12-1ubuntu0.22
jammy

released

2:3.2.12-2ubuntu1.11
mantic

released

3:4.2.4-1ubuntu2.2
noble

released

3:4.2.11-1

Показывать по

EPSS

Процентиль: 73%
0.00824
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

CVSS3: 5.3
nvd
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter are subject to a potential regular expression denial-of-service attack via a crafted string. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232 and CVE-2023-43665.

CVSS3: 5.3
debian
больше 1 года назад

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, ...

suse-cvrf
больше 1 года назад

Security update for python-Django1

suse-cvrf
больше 1 года назад

Security update for python-Django

EPSS

Процентиль: 73%
0.00824
Низкий

5.3 Medium

CVSS3