An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
History

Wed, 30 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Oct 2024 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ansible Automation Platform
CPEs cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
Vendors & Products Redhat
Redhat ansible Automation Platform

Sat, 19 Oct 2024 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Djangoproject
Djangoproject django
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*
cpe:2.3:a:djangoproject:django:5.1:*:*:*:*:*:*:*
Vendors & Products Djangoproject
Djangoproject django
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 08 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Python's Django urlize() and urlizetrunc() functions. Excessive input with a specific sequence of characters may lead to denial of service. An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
References

Wed, 25 Sep 2024 23:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Python's Django urlize() and urlizetrunc() functions. Excessive input with a specific sequence of characters may lead to denial of service.

Tue, 24 Sep 2024 23:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title python-django: Potential denial-of-service vulnerability in django.utils.html.urlize()
Weaknesses CWE-400
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-10-08T00:00:00

Updated: 2024-10-30T16:33:50.329Z

Reserved: 2024-08-24T00:00:00

Link: CVE-2024-45230

cve-icon Vulnrichment

Updated: 2024-10-08T18:34:21.663Z

cve-icon NVD

Status : Modified

Published: 2024-10-08T16:15:11.903

Modified: 2024-10-30T17:35:09.360

Link: CVE-2024-45230

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-03T00:00:00Z

Links: CVE-2024-45230 - Bugzilla