Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-56374

Опубликовано: 14 янв. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.8

Описание

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

РелизСтатусПримечание
devel

released

3:4.2.18-1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

released

1:1.11.11-1ubuntu1.21+esm9
esm-infra/focal

not-affected

2:2.2.12-1ubuntu0.27
esm-infra/xenial

needs-triage

focal

released

2:2.2.12-1ubuntu0.27
jammy

released

2:3.2.12-2ubuntu1.16
noble

released

3:4.2.11-1ubuntu1.5
oracular

released

3:4.2.15-1ubuntu1.2
plucky

released

3:4.2.18-1

Показывать по

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
redhat
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
nvd
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a potential denial-of-service attack. The undocumented and private functions clean_ipv6_address and is_valid_ipv6_address are vulnerable, as is the django.forms.GenericIPAddressField form field. (The django.db.models.GenericIPAddressField model field is not affected.)

CVSS3: 5.8
debian
5 месяцев назад

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, ...

suse-cvrf
5 месяцев назад

Security update for python-Django

CVSS3: 5.8
github
5 месяцев назад

Django has a potential denial-of-service vulnerability in IPv6 validation

5.8 Medium

CVSS3