PT-2024-6155 · Django+5 · Django+5
Seokchan Yoon
·
Published
2024-07-31
·
Updated
2026-01-03
·
CVE-2024-41991
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Django versions 4.2 through 4.2.14
Django versions 5.0 through 5.0.7
Description
The issue is related to a potential denial-of-service attack in Django, specifically affecting the
urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget. This can occur via certain inputs containing a large number of Unicode characters. The vulnerability in the django.utils.html.urlize() function is due to a mismatch in input data length parameters, which can be exploited by a remote attacker to cause a denial-of-service.Recommendations
For Django versions 4.2 through 4.2.14, update to version 4.2.15 or later.
For Django versions 5.0 through 5.0.7, update to version 5.0.8 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Django
Linuxmint
Ubuntu