An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.
History

Sun, 08 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ansible Automation Platform
CPEs cpe:/a:redhat:ansible_automation_platform:2.4::el8
cpe:/a:redhat:ansible_automation_platform:2.4::el9
Vendors & Products Redhat
Redhat ansible Automation Platform

Thu, 08 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 11:30:00 +0000

Type Values Removed Values Added
Title python-django: Memory exhaustion in django.utils.numberformat.floatformat()
Weaknesses CWE-400
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 07 Aug 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Djangoproject
Djangoproject django
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
Vendors & Products Djangoproject
Djangoproject django
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 07 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-07T00:00:00

Updated: 2024-08-08T19:39:24.621Z

Reserved: 2024-07-25T00:00:00

Link: CVE-2024-41989

cve-icon Vulnrichment

Updated: 2024-08-08T19:38:20.472Z

cve-icon NVD

Status : Modified

Published: 2024-08-07T15:15:56.030

Modified: 2024-08-08T20:35:11.140

Link: CVE-2024-41989

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-08-06T13:00:00Z

Links: CVE-2024-41989 - Bugzilla